Arbitrary Backup File Download and Upload Vulnerability Affects File Manager Pro Plugin
CVE-2024-8746

8.8HIGH

Key Information:

Vendor
Filemanagerpro
Status
File Manager
Vendor
CVE Published:
16 October 2024

Summary

The File Manager Pro plugin for WordPress is susceptible to a vulnerability that allows unauthenticated attackers to perform arbitrary backup file downloads and uploads. This vulnerability arises from inadequate file type validation within the 'mk_file_folder_manager_shortcode' ajax action, impacting all versions through 8.3.9. If an attacker gains access to the File Manager under the permission of an authorized administrator, they can exploit this flaw to download sensitive files or upload malicious backups, which can pave the way for potential remote code execution. Website administrators are advised to take immediate action to mitigate this risk.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

Collectors

NVD Database
.