Directory Traversal Vulnerability in WordPress Plugins Using elFinder by Studio 42
CVE-2025-0818
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 13 August 2025
What is CVE-2025-0818?
Several WordPress plugins that implement elFinder versions 2.1.64 and earlier are vulnerable to a directory traversal issue. This vulnerability enables unauthorized attackers to delete arbitrary files from the server. For successful exploitation, the site owner must deliberately expose an instance of the file manager to users. It is imperative for site administrators to review their plugin setups and apply necessary patches to mitigate this risk.
Affected Version(s)
Advanced File Manager – Ultimate WP File Manager And Document Library Solution * <= 5.3.6
File Manager * <= 8.4.2
File Manager Pro – Filester * <= 1.8.9