Executive brief
Multiple popular WordPress file management plugins are vulnerable to a security flaw that allows logged-in users to execute unauthorized commands on the web server. These plugins are typically used by administrators to manage site files directly through the WordPress dashboard. If exploited, an attacker could take full control of the website and its underlying server, potentially leading to data theft or complete service disruption.
Technical details
Multiple WordPress plugins utilizing elFinder components fail to properly escape parameters before passing them to shell commands during image processing operations. This leads to an OS Command Injection vulnerability. The flaw is exploitable by authenticated users and specifically occurs when the server is configured to use the ImageMagick 'convert' CLI utility in the absence of the PHP imagick or GD extensions. An attacker can leverage this to execute arbitrary code with the privileges of the web server user. Patches have been released for all affected plugins (FileOrganizer 1.1.9, Advanced File Manager 5.4.12, Filester 2.1.1, and File Manager 8.0.4).
Affected products
- Unknown FileOrganizer < 1.1.9
- Unknown Advanced File Manager < 5.4.12
- Unknown File Manager Pro (Filester) < 2.1.1
- Unknown File Manager < 8.0.4
Timeline
- 2026-06-15: disclosed: Initial public disclosure
- 2026-07-06: advisory: NVD publication date