CVE-2024-2654: File Manager <= 7.2.5 - Authenticated (Administrator+) Directory Traversal
The File Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.2.5 via the fmdownloadbackup function. This makes it possible for authenticated attackers, with administrator access and above, to read the contents of arbitrary zip files on the server, which can contain sensitive information.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2654?
CVE-2024-2654 is classified as a high severity vulnerability due to its potential for directory traversal attacks.
How do I fix CVE-2024-2654?
To fix CVE-2024-2654, you should upgrade the WordPress File Manager plugin to version 7.2.6 or later.
Who is affected by CVE-2024-2654?
CVE-2024-2654 affects all versions of the WordPress File Manager plugin up to and including 7.2.5.
What kind of attacks can CVE-2024-2654 facilitate?
CVE-2024-2654 can facilitate authenticated attackers with administrator access to read arbitrary zip files on the server.
What functions are vulnerable in CVE-2024-2654?
The fm_download_backup function in the WordPress File Manager plugin is vulnerable in CVE-2024-2654.