
Cloud Vulnerability DB
A community-led vulnerabilities database
The File Manager and File Manager Pro plugins for WordPress contain a Directory Traversal vulnerability (CVE-2023-6825) affecting versions up to 7.2.1 (free version) and 8.3.4 (Pro version). The vulnerability exists in the mk_file_folder_manager_action_callback_shortcode function via the target parameter (NVD, Security Online).
The vulnerability is rated as Critical with a CVSS score of 9.9. It allows attackers to traverse directories through the target parameter in the mk_file_folder_manager_action_callback_shortcode function. In the free version, administrator access is required for exploitation. However, the Pro version is more vulnerable as it allows file manager embedding via shortcode and permits admins to grant file handling privileges to lower-level users (NVD).
Successful exploitation allows attackers to read the contents of arbitrary files on the server, potentially exposing sensitive information. Additionally, attackers can upload files into directories other than the intended directory for file uploads. With over a million active installations, this vulnerability poses a significant risk to WordPress websites (Security Online).
The vulnerability requires different access levels depending on the version. For the free version, administrator access is required to exploit the vulnerability. The Pro version presents a higher risk as it can be exploited by lower-level users if they have been granted file handling privileges through the shortcode functionality (NVD).
Users should immediately update to File Manager version 7.2.2 or later (free version) or File Manager Pro version 8.3.5 or later. These versions contain patches that address the directory traversal vulnerability (Security Online).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."