The File Manager Pro plugin for WordPress is vulnerable to arbitrary backup file downloads and uploads due to missing file type validation via the 'mk_file_folder_manager_shortcode' ajax action in all versions up to, and including, 8.3.9. This makes it possible for unauthenticated attackers, if granted access to the File Manager by an administrator, to download and upload arbitrary backup files on the affected site's server which may make remote code execution possible.
Metrics
Affected Vendors & Products
References
History
Thu, 17 Oct 2024 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Filemanagerpro file Manager
|
|
CPEs | cpe:2.3:a:filemanagerpro:file_manager:*:*:*:*:pro:wordpress:*:* | |
Vendors & Products |
Filemanagerpro file Manager
|
Wed, 16 Oct 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Filemanagerpro
Filemanagerpro file Manager Pro |
|
CPEs | cpe:2.3:a:filemanagerpro:file_manager_pro:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Filemanagerpro
Filemanagerpro file Manager Pro |
|
Metrics |
ssvc
|
Wed, 16 Oct 2024 07:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The File Manager Pro plugin for WordPress is vulnerable to arbitrary backup file downloads and uploads due to missing file type validation via the 'mk_file_folder_manager_shortcode' ajax action in all versions up to, and including, 8.3.9. This makes it possible for unauthenticated attackers, if granted access to the File Manager by an administrator, to download and upload arbitrary backup files on the affected site's server which may make remote code execution possible. | |
Title | File Manager Pro <= 8.3.9 - Unauthenticated Backup File Download and Upload | |
Weaknesses | CWE-434 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-10-16T06:43:35.462Z
Updated: 2024-10-16T18:03:56.333Z
Reserved: 2024-09-12T01:57:09.799Z
Link: CVE-2024-8746
Vulnrichment
Updated: 2024-10-16T17:44:59.659Z
NVD
Status : Analyzed
Published: 2024-10-16T07:15:16.537
Modified: 2024-10-17T18:22:18.277
Link: CVE-2024-8746
Redhat
No data.