Description
The File Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.4. This is due to missing or incorrect nonce validation on the wp_file_manager page that includes files through the 'lang' parameter. This makes it possible for unauthenticated attackers to include local JavaScript files that can be leveraged to achieve RCE via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This issue was partially patched in version 7.2.4, and fully patched in 7.2.5.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-17286 | The File Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.4. This is due to missing or incorrect nonce validation on the wp_file_manager page that includes files through the 'lang' parameter. This makes it possible for unauthenticated attackers to include local JavaScript files that can be leveraged to achieve RCE via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This issue was partially patched in version 7.2.4, and fully patched in 7.2.5. |
References
History
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | File Manager <= 7.2.4 - Cross-Site Request Forgery to Local JS File Inclusion |
Wed, 25 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mndpsingh287
Mndpsingh287 file Manager |
|
| CPEs | cpe:2.3:a:mndpsingh287:file_manager:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mndpsingh287
Mndpsingh287 file Manager |
|
| Metrics |
ssvc
|
Mon, 19 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Filemanagerpro
Filemanagerpro file Manager |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:filemanagerpro:file_manager:*:*:*:*:free:wordpress:*:* | |
| Vendors & Products |
Filemanagerpro
Filemanagerpro file Manager |
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:54:28.341Z
Reserved: 2024-02-15T15:53:38.014Z
Link: CVE-2024-1538
Updated: 2024-08-01T18:40:21.445Z
Status : Modified
Published: 2024-03-21T04:15:09.117
Modified: 2026-04-08T18:20:42.900
Link: CVE-2024-1538
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD