CVE-2018-25105: File Manager <= 3.0 - Unauthenticated Arbitrary File Upload/Download
The File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the /inc/root.php file in versions up to, and including, 3.0. This makes it possible for unauthenticated attackers to download arbitrary files from the server and upload arbitrary files that can be used for remote code execution.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-25105?
CVE-2018-25105 is classified as a high severity vulnerability due to the potential for unauthorized file access.
How do I fix CVE-2018-25105?
To fix CVE-2018-25105, update the File Manager plugin for WordPress to version 3.1 or higher.
Who is affected by CVE-2018-25105?
CVE-2018-25105 affects users of the File Manager Pro plugin for WordPress versions 3.0 and older.
What can attackers do with CVE-2018-25105?
With CVE-2018-25105, attackers can exploit the vulnerability to download arbitrary files from the server.
What are the implications of CVE-2018-25105 for website security?
CVE-2018-25105 can lead to unauthorized access to sensitive data and potential compromise of the affected WordPress site.