CVE-2025-0818: Multiple elFinder Plugins <= (Various Versions) - Directory Traversal to Arbitrary File Deletion
Several WordPress plugins using elFinder versions 2.1.64 and prior are vulnerable to Directory Traversal in various versions. This makes it possible for unauthenticated attackers to delete arbitrary files. Successful exploitation of this vulnerability requires a site owner to explicitly make an instance of the file manager available to users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0818?
CVE-2025-0818 is considered to be a high-severity vulnerability due to its potential for allowing unauthenticated attackers to delete arbitrary files.
How do I fix CVE-2025-0818?
To fix CVE-2025-0818, upgrade elFinder to version 2.1.65 or later.
What types of WordPress plugins are affected by CVE-2025-0818?
CVE-2025-0818 affects several WordPress plugins that utilize elFinder versions 2.1.64 and earlier.
Can CVE-2025-0818 be exploited without authentication?
Yes, CVE-2025-0818 can be exploited by unauthenticated attackers, making it particularly dangerous.
What is the main issue caused by CVE-2025-0818?
The main issue caused by CVE-2025-0818 is a Directory Traversal vulnerability, allowing attackers to manipulate file paths and delete files.