CVE-2024-8746: File Manager Pro <= 8.3.9 - Unauthenticated Backup File Download and Upload
The File Manager Pro plugin for WordPress is vulnerable to arbitrary backup file downloads and uploads due to missing file type validation via the 'mkfilefoldermanagershortcode' ajax action in all versions up to, and including, 8.3.9. This makes it possible for unauthenticated attackers, if granted access to the File Manager by an administrator, to download and upload arbitrary backup files on the affected site's server which may make remote code execution possible.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8746?
CVE-2024-8746 is considered high severity due to its potential to allow unauthenticated users to download and upload arbitrary backup files.
How do I fix CVE-2024-8746?
To fix CVE-2024-8746, update the File Manager Pro plugin to version 8.3.10 or later.
What type of vulnerability is CVE-2024-8746?
CVE-2024-8746 is an arbitrary file upload and download vulnerability caused by missing file type validation.
Which versions of File Manager Pro are affected by CVE-2024-8746?
All versions of the File Manager Pro plugin for WordPress up to and including 8.3.9 are affected by CVE-2024-8746.
Can unauthenticated users exploit CVE-2024-8746?
Yes, unauthenticated users can exploit CVE-2024-8746 to access and manipulate backup files.