CVE-2018-16966: CSRF
There is a CSRF vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wpfilemanagerroot publicpath parameter.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the CSRF vulnerability in the mndpsingh287 File Manager plugin?
The vulnerability ID for the CSRF vulnerability in the mndpsingh287 File Manager plugin is CVE-2018-16966.
What is the affected version of the mndpsingh287 File Manager plugin?
The affected version of the mndpsingh287 File Manager plugin is version 3.0.
What is the severity of CVE-2018-16966?
The severity of CVE-2018-16966 is rated as high with a severity value of 8.8.
How does the CSRF vulnerability in the mndpsingh287 File Manager plugin occur?
The CSRF vulnerability in the mndpsingh287 File Manager plugin occurs via the page=wp_file_manager_root public_path parameter.
Are there any references for more information about CVE-2018-16966?
Yes, you can find more information about CVE-2018-16966 at the following references: [Reference 1](https://ansawaf.blogspot.com/2019/04/file-manager-plugin-wordpress-plugin.html), [Reference 2](https://wordpress.org/plugins/wp-file-manager/#developers), [Reference 3](https://wpvulndb.com/vulnerabilities/9614).