Directory Traversal Vulnerability in WordPress Plugins Using elFinder by Studio 42
CVE-2025-0818

6.5MEDIUM

What is CVE-2025-0818?

Several WordPress plugins that implement elFinder versions 2.1.64 and earlier are vulnerable to a directory traversal issue. This vulnerability enables unauthorized attackers to delete arbitrary files from the server. For successful exploitation, the site owner must deliberately expose an instance of the file manager to users. It is imperative for site administrators to review their plugin setups and apply necessary patches to mitigate this risk.

Affected Version(s)

Advanced File Manager – Ultimate WP File Manager And Document Library Solution * <= 5.3.6

File Manager * <= 8.4.2

File Manager Pro – Filester * <= 1.8.9

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kevin Wydler
.
CVE-2025-0818 : Directory Traversal Vulnerability in WordPress Plugins Using elFinder by Studio 42