First published: Mon Oct 16 2023(Updated: )
The File Manager Pro WordPress plugin before 1.8 does not properly check the CSRF nonce in the `fs_connector` AJAX action. This allows attackers to make highly privileged users perform unwanted file system actions via CSRF attacks by using GET requests, such as uploading a web shell.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ninjateam Filester | <1.8 | |
<1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-4827 is high with a severity value of 8.8.
CVE-2023-4827 allows attackers to perform unwanted file system actions via CSRF attacks, such as uploading a web shell, by exploiting the plugin's improper CSRF nonce check in the fs_connector AJAX action.
Versions before 1.8 of the File Manager Pro WordPress plugin are affected by CVE-2023-4827.
Attackers can make highly privileged users perform unwanted file system actions, such as uploading a web shell, by exploiting CVE-2023-4827 through CSRF attacks.
Yes, updating the File Manager Pro WordPress plugin to version 1.8 or later addresses CVE-2023-4827 vulnerability.