Description
Several WordPress plugins using elFinder versions 2.1.64 and prior are vulnerable to Directory Traversal in various versions. This makes it possible for unauthenticated attackers to delete arbitrary files. Successful exploitation of this vulnerability requires a site owner to explicitly make an instance of the file manager available to users.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-24540 | Several WordPress plugins using elFinder versions 2.1.64 and prior are vulnerable to Directory Traversal in various versions. This makes it possible for unauthenticated attackers to delete arbitrary files. Successful exploitation of this vulnerability requires a site owner to explicitly make an instance of the file manager available to users. |
References
History
Thu, 14 Aug 2025 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Wed, 13 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 13 Aug 2025 04:00:00 +0000
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:20:11.705Z
Reserved: 2025-01-28T21:23:43.968Z
Link: CVE-2025-0818
Updated: 2025-08-13T14:01:49.584Z
Status : Awaiting Analysis
Published: 2025-08-13T04:16:08.373
Modified: 2025-08-13T17:33:46.673
Link: CVE-2025-0818
No data.
OpenCVE Enrichment
Updated: 2025-08-13T21:47:05Z
Weaknesses
EUVD