Directory Traversal Vulnerability in WordPress Plugins Using elFinder by Studio 42
CVE-2025-0818
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 13 August 2025
What is CVE-2025-0818?
Several WordPress plugins that implement elFinder versions 2.1.64 and earlier are vulnerable to a directory traversal issue. This vulnerability enables unauthorized attackers to delete arbitrary files from the server. For successful exploitation, the site owner must deliberately expose an instance of the file manager to users. It is imperative for site administrators to review their plugin setups and apply necessary patches to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Advanced File Manager β Ultimate WP File Manager And Document Library Solution * <= 5.3.6
File Manager * <= 8.4.2
File Manager Pro β Filester * <= 1.8.9
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved