Impact
The FileOrganizer WordPress plugin before version 1.2.0 does not perform MIME‑type validation when executing elFinder file‑management operations. This flaw permits any authenticated user who has been granted the file‑manager privilege—either through the default role or via the premium add‑on that elevates sub‑administrators—to upload arbitrary PHP files to a publicly accessible directory. When the web server processes the uploaded file, the embedded PHP code is executed, giving the attacker full remote code execution within the context of the WordPress site.
Affected Systems
All installations of the FileOrganizer plugin with a version number lower than 1.2.0 are impacted. The vulnerability is only exploitable on sites where a WordPress user has been assigned the file‑manager role or where the premium add‑on has extended these privileges to sub‑administrators; no other vendors or products are included in the affected set.
Risk and Exploitability
The CVSS score of 8.8 places this issue in the high‑severity category, while the EPSS score of less than 1% indicates a very low current exploitation probability. It is not listed in the CISA KEV catalog. Exploitation requires prior authentication and permission to use the elFinder interface; once achieved, an attacker can upload malicious PHP code that the web server executes, potentially allowing complete compromise of the hosting environment.
OpenCVE Enrichment