Junglewise Threat Intelligence

CVE-2020-25213: WordPress File Manager Plugin Remote Code Execution Vulnerability

CVE-2020-25213 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Vendors: Wordpress.

Executive brief

The WordPress File Manager plugin before version 6.9 contains a remote code execution vulnerability due to an unsafe elFinder connector file. Unauthenticated attackers can upload and execute arbitrary PHP code by leveraging the elFinder upload, mkfile, or put commands.

Affected products

  • webdesi9 File Manager (wp-file-manager) before 6.9

Timeline

  • 2020-08: exploited: Exploited in the wild in August and September 2020.
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2021-11-03: disclosed