Description
WordPress Plugin Wp-FileManager is prone to a vulnerability that attackers can exploit to upload arbitrary PHP script code and execute it in the context of the webserver process. WordPress Plugin Wp-FileManager version 1.2 is vulnerable; other versions may also be affected.
Remediation
Update to the latest version
References
http://www.exploit-db.com/exploits/4844/
http://packetstormsecurity.com/files/view/62341/wpfile-upload.txt
Related Vulnerabilities
MySQL CVE-2018-3063 Vulnerability (CVE-2018-3063)
WordPress Plugin jQuery Tagline Rotator Cross-Site Scripting (0.1.5)
WordPress Plugin Catch Themes Demo Import Security Bypass (1.5)
WordPress Plugin Comment Extra Fields Multiple Cross-Site Scripting Vulnerabilities (1.7)
Dolibarr Missing Authorization Vulnerability (CVE-2018-10092)