CVE Feed

    Dashboard / CVE / CVE-2023-6825

    CVE-2023-6825

    The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and including version 7.2.1 (free version) and 8.3.4 (Pro version) via the target parameter in the mk_file_folder_manager_action_callback_shortcode function. This makes it possible for attackers to read the contents of arbitrary files on the server, which can contain sensitive information and to upload files into directories other than the intended directory for file uploads. The free version requires Administrator access for this vulnerability to be exploitable. The Pro version allows a file manager to be embedded via a shortcode and also allows admins to grant file handling privileges to other user levels, which could lead to this vulnerability being exploited by lower-level users.

    Published:Mar 13, 2024
    Last Modified:Apr 8, 2026
    EPS:Mar 13, 2024
    EPSS Score:0.03748
    CVSS Score:9.9

    Affected Products

    Vendor
    File Manager Project
    Product
    File Manager
    Vendor
    Filemanagerpro
    Product
    File Manager Pro
    Vendor
    Mndpsingh287
    Product
    File Manager

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High