Impact
The vulnerability arises from a directory traversal flaw in elFinder classes used by several WordPress plugins. An attacker who can reach the exposed file manager instance can craft a path that writes outside of the intended workspace, allowing deletion of any file on the server. The flaw has a CWE‑22 designation, and because it does not involve credential compromise, the primary impact is integrity and availability loss of protected files.
Affected Systems
Products impacted include File Manager Pro, ninjateam’s Filester, and saadiqbal’s Advanced File ManagerUltimate File Manager for WordPress. All affected plugins incorporate elFinder 2.1.64 or older versions, which implement the vulnerable directory handling logic.
Risk and Exploitability
The CVSS score of 6.5 reflects a moderate severity, while an EPSS score of about 1% assigns a low exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Attackers need only unauthenticated access to the file manager URL and the tool must be made publicly available; the flaw can be exploited remotely over the web and permits deletion of arbitrary files.
OpenCVE Enrichment
EUVD