Arbitrary Backup File Download and Upload Vulnerability Affects File Manager Pro Plugin
CVE-2024-8746
What is CVE-2024-8746?
The File Manager Pro plugin for WordPress is susceptible to a vulnerability that allows unauthenticated attackers to perform arbitrary backup file downloads and uploads. This vulnerability arises from inadequate file type validation within the 'mk_file_folder_manager_shortcode' ajax action, impacting all versions through 8.3.9. If an attacker gains access to the File Manager under the permission of an authorized administrator, they can exploit this flaw to download sensitive files or upload malicious backups, which can pave the way for potential remote code execution. Website administrators are advised to take immediate action to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published