Arbitrary File Uploads Vulnerability in File Manager Pro for WordPress
CVE-2024-7559
What is CVE-2024-7559?
The File Manager Pro plugin for WordPress is susceptible to arbitrary file uploads due to inadequate file type validation and lack of appropriate capability checks in the mk_file_folder_manager AJAX action. This vulnerability affects all versions up to and including 8.3.7, enabling authenticated users with Subscriber-level access and above to upload potentially malicious files to the server. By exploiting this flaw, attackers could potentially execute remote code on the affected WordPress site, leading to significant security breaches.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
File Manager Pro * <= 8.3.7
References
EPSS Score
12% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved