Back to overview

CVE-2023-6825

CRITICAL
9.9
CVSS 3.1
Description
The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and including version 7.2.1 (free version) and 8.3.4 (Pro version) via the target parameter in the mk_file_folder_manager_action_callback_shortcode function. This makes it possible for attackers to read the contents of arbitrary files on the server, which can contain sensitive information and to upload files into directories other than the intended directory for file uploads. The free version requires Administrator access for this vulnerability to be exploitable. The Pro version allows a file manager to be embedded via a shortcode and also allows admins to grant file handling privileges to other user levels, which could lead to this vulnerability being exploited by lower-level users.

Metadata

CVE ID
CVE-2023-6825
State
PUBLISHED
Assigner
Wordfence
Reserved
2023-12-14 18:54 UTC
Published
2024-03-13 15:27 UTC
Last updated
2026-04-08 17:09 UTC
Primary CWE
CWE-23
CWE-23 Relative Path Traversal
Vendor / Product
mndpsingh287 / File Manager
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (2)
VendorProductPlatformVersions
File Manager File Manager Pro 0 ≤ 8.3.4
mndpsingh287 File Manager 0 ≤ 7.2.1
Weakness (CWE)
CWESourceDescription
CWE-23 cna CWE-23 Relative Path Traversal
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Back to overview