sales@hackhalt.com

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total25
Critical3
High15
Medium7
Reset
Showing 1-20 of 25 records
Threat Entry Updated 2026-08-26

File Manager - Denial of Service (CVE-2026-17540)

The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a subscriber, to read and delete arbitrary files under the WordPress installation directory, which could lead to the disclosure of the site's configuration secrets and to denial of service.

PLUGIN File Manager

CVE-2026-17540

HIGH CVSS 8.8 2026-08-10
Threat Entry Updated 2026-08-26

File Manager - Broken Access Control (CVE-2026-17542)

The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connector endpoints, allowing any authenticated user, such as a subscriber, to browse the entire WordPress installation directory and download files of certain types from it, including archives and documents which may contain sensitive data.

PLUGIN File Manager

CVE-2026-17542

HIGH CVSS 7.5 2026-08-10
Threat Entry Updated 2026-08-26

File Manager - Security Vulnerability (CVE-2026-17541)

The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to read its file activity log, disclosing the file operations performed on the site, the paths involved and the name of the user who performed them.

PLUGIN File Manager

CVE-2026-17541

HIGH CVSS 7.5 2026-08-10
Threat Entry Updated 2026-08-12

File Manager - Remote Code Execution (CVE-2026-15991)

The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to read and delete arbitrary files on the server, which can lead to remote code execution when the right file is deleted (such as wp-config.php). The bypass is triggered by passing cmd=rm or cmf=file in the URL query string of a POST request: elFinder's bind registration reads the command…

PLUGIN File Manager

CVE-2026-15991

HIGH CVSS 8.8 2026-08-06
Threat Entry Updated 2026-06-17

File Manager - Cross-Site Scripting (XSS) (CVE-2025-1725)

The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

PLUGIN File Manager

CVE-2025-1725

MEDIUM CVSS 6.4 2025-06-03
Threat Entry Updated 2026-06-17

File Manager - Cross-Site Request Forgery (CSRF) (CVE-2024-8507)

The File Manager Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.3.9. This is due to missing or incorrect nonce validation on the 'mk_file_folder_manager' ajax action. This makes it possible for unauthenticated attackers to upload arbitrary files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN File Manager

CVE-2024-8507

HIGH CVSS 8.8 2024-10-16
Threat Entry Updated 2026-06-17

File Manager - Remote Code Execution (CVE-2024-8746)

The File Manager Pro plugin for WordPress is vulnerable to arbitrary backup file downloads and uploads due to missing file type validation via the 'mk_file_folder_manager_shortcode' ajax action in all versions up to, and including, 8.3.9. This makes it possible for unauthenticated attackers, if granted access to the File Manager by an administrator, to download and upload arbitrary backup files on the affected site's server which may make remote code execution possible.

PLUGIN File Manager

CVE-2024-8746

HIGH CVSS 7.5 2024-10-16
Threat Entry Updated 2026-06-17

File Manager - Arbitrary File Upload (CVE-2024-8918)

The File Manager Pro plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and including, 8.3.9. This is due to a lack of proper checks on allowed file types. This makes it possible for unauthenticated attackers, with permissions granted by an administrator, to upload .css and .js files, which could lead to Stored Cross-Site Scripting.

PLUGIN File Manager

CVE-2024-8918

HIGH CVSS 7.4 2024-10-16
Threat Entry Updated 2026-06-17

File Manager - Remote Code Execution (CVE-2018-25105)

The File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the /inc/root.php file in versions up to, and including, 3.0. This makes it possible for unauthenticated attackers to download arbitrary files from the server and upload arbitrary files that can be used for remote code execution.

PLUGIN File Manager

CVE-2018-25105

CRITICAL CVSS 9.8 2024-10-16
Threat Entry Updated 2026-06-17

File Manager - Remote Code Execution (CVE-2024-7770)

The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload' function in all versions up to, and including, 6.5.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted upload permissions by an administrator, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN File Manager

CVE-2024-7770

HIGH CVSS 8.8 2024-09-10
Threat Entry Updated 2026-06-17

File Manager - Remote Code Execution (CVE-2024-7627)

The Bit File Manager plugin for WordPress is vulnerable to Remote Code Execution in versions 6.0 to 6.5.5 via the 'checkSyntax' function. This is due to writing a temporary file to a publicly accessible directory before performing file validation. This makes it possible for unauthenticated attackers to execute code on the server if an administrator has allowed Guest User read permissions.

PLUGIN File Manager

CVE-2024-7627

HIGH CVSS 8.1 2024-09-05
Threat Entry Updated 2026-06-17

File Manager - Path Traversal (CVE-2024-2654)

The File Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.2.5 via the fm_download_backup function. This makes it possible for authenticated attackers, with administrator access and above, to read the contents of arbitrary zip files on the server, which can contain sensitive information.

PLUGIN File Manager

CVE-2024-2654

MEDIUM CVSS 6.8 2024-04-09
Threat Entry Updated 2026-06-17

File Manager - Remote Code Execution (CVE-2024-1538)

The File Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.4. This is due to missing or incorrect nonce validation on the wp_file_manager page that includes files through the 'lang' parameter. This makes it possible for unauthenticated attackers to include local JavaScript files that can be leveraged to achieve RCE via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This issue was partially patched in version 7.2.4, and fully…

PLUGIN File Manager

CVE-2024-1538

HIGH CVSS 8.8 2024-03-21
Threat Entry Updated 2026-06-17

File Manager - Path Traversal (CVE-2023-6825)

The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and including version 7.2.1 (free version) and 8.3.4 (Pro version) via the target parameter in the mk_file_folder_manager_action_callback_shortcode function. This makes it possible for attackers to read the contents of arbitrary files on the server, which can contain sensitive information and to upload files into directories other than the intended directory for file uploads. The free version requires Administrator access for this vulnerability to be exploitable. The Pro version allows a file…

PLUGIN File Manager

CVE-2023-6825

CRITICAL CVSS 9.9 2024-03-13
Threat Entry Updated 2026-06-17

File Manager - Information Disclosure (CVE-2024-0761)

The File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.2.1 due to insufficient randomness in the backup filenames, which use a timestamp plus 4 random digits. This makes it possible for unauthenticated attackers, to extract sensitive data including site backups in configurations where the .htaccess file in the directory does not block access.

PLUGIN File Manager

CVE-2024-0761

HIGH CVSS 8.1 2024-02-05
Threat Entry Updated 2026-06-17

File Manager - Arbitrary File Upload (CVE-2023-6846)

The File Manager Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.3.4 via the mk_check_filemanager_php_syntax AJAX function. This makes it possible for authenticated attackers, with subscriber access and above, to execute code on the server. Version 8.3.5 introduces a capability check that prevents users lower than admin from executing this function.

PLUGIN File Manager

CVE-2023-6846

HIGH CVSS 8.8 2024-02-05
Threat Entry Updated 2026-06-17

File Manager - PHP Object Injection (CVE-2022-47599)

Deserialization of Untrusted Data vulnerability in File Manager by Bit Form Team File Manager – 100% Free & Open Source File Manager Plugin for WordPress | Bit File Manager.This issue affects File Manager – 100% Free & Open Source File Manager Plugin for WordPress | Bit File Manager: from n/a through 5.2.7.

PLUGIN File Manager

CVE-2022-47599

MEDIUM CVSS 5.5 2023-12-20
Threat Entry Updated 2026-06-17

File Manager - Security Vulnerability (CVE-2023-5907)

The File Manager WordPress plugin before 6.3 does not restrict the file managers root directory, allowing an administrator to set a root outside of the WordPress root directory, giving access to system files and directories even in a multisite setup, where site administrators should not be allowed to modify the sites files.

PLUGIN File Manager

CVE-2023-5907

MEDIUM CVSS 6.5 2023-12-11
Threat Entry Updated 2022-05-03

File Manager - Remote Code Execution (CVE-2020-25213)

The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php extension. This, for example, allows attackers to run the elFinder upload (or mkfile and put) command to write PHP code into the wp-content/plugins/wp-file-manager/lib/files/ directory. This was exploited in the wild in August and September 2020.

PLUGIN File Manager

CVE-2020-25213

CRITICAL CVSS 10.0 2021-11-03
Threat Entry Updated 2026-06-17

File Manager - Cross-Site Scripting (XSS) (CVE-2021-24177)

In the default configuration of the File Manager WordPress plugin before 7.1, a Reflected XSS can occur on the endpoint /wp-admin/admin.php?page=wp_file_manager_properties when a payload is submitted on the User-Agent parameter. The payload is then reflected back on the web application response.

PLUGIN File Manager

CVE-2021-24177

MEDIUM CVSS 5.4 2021-04-05