CVE-2020-25213
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- WordPress File Manager Plugin Remote Code Execution Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php extension. This, for example, allows attackers to run the elFinder upload (or mkfile and put) command to write PHP code into the wp-content/plugins/wp-file-manager/lib/files/ directory. This was exploited in the wild in August and September 2020.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 97% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-434
מוצרים מושפעים
filemanagerpro: file manager
קישורים
- https://plugins.trac.wordpress.org/changeset/2373068 Patch
- https://plugins.trac.wordpress.org/changeset/2373068 Patch
- http://packetstormsecurity.com/files/160003/WordPress-File-Manager-6.8-Remote-… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/171650/WordPress-File-Manager-6.9-Shell-U… ExploitThird Party AdvisoryVDB Entry
- https://github.com/w4fz5uck5/wp-file-manager-0day ExploitThird Party Advisory
- https://seravo.com/blog/0-day-vulnerability-in-wp-file-manager/ ExploitThird Party Advisory
- https://wordfence.com/blog/2020/09/700000-wordpress-users-affected-by-zero-day… ExploitThird Party Advisory
- http://packetstormsecurity.com/files/160003/WordPress-File-Manager-6.8-Remote-… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/171650/WordPress-File-Manager-6.9-Shell-U… ExploitThird Party AdvisoryVDB Entry
- https://github.com/w4fz5uck5/wp-file-manager-0day ExploitThird Party Advisory