CVE-2024-0761: File Manager <= 7.2.1 - Sensitive Information Exposure via Backup Filenames
The File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.2.1 due to insufficient randomness in the backup filenames, which use a timestamp plus 4 random digits. This makes it possible for unauthenticated attackers, to extract sensitive data including site backups in configurations where the .htaccess file in the directory does not block access.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0761?
CVE-2024-0761 has a medium severity rating due to the potential for sensitive information exposure.
How do I fix CVE-2024-0761?
To fix CVE-2024-0761, update the File Manager plugin for WordPress to version 7.2.2 or later.
Who is affected by CVE-2024-0761?
All users of the File Manager plugin for WordPress versions up to and including 7.2.1 are affected by CVE-2024-0761.
What type of vulnerability is CVE-2024-0761?
CVE-2024-0761 is categorized as a Sensitive Information Exposure vulnerability.
What can attackers do with CVE-2024-0761?
Unauthenticated attackers can exploit CVE-2024-0761 to extract sensitive information from the vulnerable File Manager plugin.