Impact
The FileOrganizer WordPress plugin before version 1.2.0 fails to validate the MIME type of files when performing elFinder file‑management operations. This omission permits any authenticated user who has been granted the file‑manager privilege—either through the default role or via the premium add‑on that elevates sub‑administrators—to upload arbitrary PHP files to the publicly accessible upload directory. When the web server parses the uploaded file, the embedded PHP code is executed, giving the attacker full remote code execution within the context of the WordPress site.
Affected Systems
All installations of the FileOrganizer WordPress plugin with a version number lower than 1.2.0 are affected. The flaw is only triggered for sites where a WordPress user has been granted the file‑manager role or where the premium add‑on has extended these privileges to sub‑administrators. No other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS score of 8.8 places this vulnerability in the high‑severity class, while the EPSS score of less than 1% indicates a low current exploitation probability. The flaw is not present in the CISA KEV catalog. Successful exploitation requires prior authentication and permission to use the elFinder interface; once achieved, an attacker can upload malicious PHP code that the web server then executes, potentially allowing complete compromise of the hosting environment.
OpenCVE Enrichment