Arbitrary Backup File Download and Upload Vulnerability Affects File Manager Pro Plugin
CVE-2024-8746
8.8HIGH
Key Information:
- Vendor
- Filemanagerpro
- Status
- File Manager
- Vendor
- CVE Published:
- 16 October 2024
Summary
The File Manager Pro plugin for WordPress is susceptible to a vulnerability that allows unauthenticated attackers to perform arbitrary backup file downloads and uploads. This vulnerability arises from inadequate file type validation within the 'mk_file_folder_manager_shortcode' ajax action, impacting all versions through 8.3.9. If an attacker gains access to the File Manager under the permission of an authorized administrator, they can exploit this flaw to download sensitive files or upload malicious backups, which can pave the way for potential remote code execution. Website administrators are advised to take immediate action to mitigate this risk.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Collectors
NVD Database