Description
WordPress Plugin File Manager is prone to multiple vulnerabilities, including security bypass and information disclosure vulnerabilities. An attacker may leverage these issues to perform otherwise restricted actions and subsequently delete or restore backups, or to obtain sensitive information that may help in launching further attacks. WordPress Plugin File Manager version 4.8 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.9 or latest
References
https://www.webarxsecurity.com/wordpress-plugin-file-manager-multiple-vulnerabilities/
https://plugins.svn.wordpress.org/wp-file-manager/trunk/readme.txt
Related Vulnerabilities
Artifactory Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-10324)
Envoy Proxy Use After Free Vulnerability (CVE-2023-35942)
WordPress 4.8.x PHP Object Injection (4.8 - 4.8.16)
WebLogic CVE-2020-5421 Vulnerability (CVE-2020-5421)
WordPress Plugin WP Discourse Unspecified Vulnerability (0.9.7)