The File Manager Pro plugin for WordPress is vulnerable to arbitrary backup file downloads and uploads due to missing file type validation via the 'mk_file_folder_manager_shortcode' ajax action in all versions up to, and including, 8.3.9. This makes it possible for unauthenticated attackers, if granted access to the File Manager by an administrator, to download and upload arbitrary backup files on the affected site's server which may make remote code execution possible.
History

Thu, 17 Oct 2024 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Filemanagerpro file Manager
CPEs cpe:2.3:a:filemanagerpro:file_manager:*:*:*:*:pro:wordpress:*:*
Vendors & Products Filemanagerpro file Manager

Wed, 16 Oct 2024 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Filemanagerpro
Filemanagerpro file Manager Pro
CPEs cpe:2.3:a:filemanagerpro:file_manager_pro:*:*:*:*:*:wordpress:*:*
Vendors & Products Filemanagerpro
Filemanagerpro file Manager Pro
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Oct 2024 07:00:00 +0000

Type Values Removed Values Added
Description The File Manager Pro plugin for WordPress is vulnerable to arbitrary backup file downloads and uploads due to missing file type validation via the 'mk_file_folder_manager_shortcode' ajax action in all versions up to, and including, 8.3.9. This makes it possible for unauthenticated attackers, if granted access to the File Manager by an administrator, to download and upload arbitrary backup files on the affected site's server which may make remote code execution possible.
Title File Manager Pro <= 8.3.9 - Unauthenticated Backup File Download and Upload
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-10-16T06:43:35.462Z

Updated: 2024-10-16T18:03:56.333Z

Reserved: 2024-09-12T01:57:09.799Z

Link: CVE-2024-8746

cve-icon Vulnrichment

Updated: 2024-10-16T17:44:59.659Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-16T07:15:16.537

Modified: 2024-10-17T18:22:18.277

Link: CVE-2024-8746

cve-icon Redhat

No data.