Loading
Generated remediation guidance and an executive summary. No account required.
The File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the /inc/root.php file in versions up to, and including, 3.0. This makes it possible for unauthenticated attackers to download arbitrary files from the server and upload arbitrary files that can be used for remote code execution.
Use CWE-862, Filemanagerpro vendor hub and File Manager product page to widen CVE-2018-25105 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-25213, CVE-2024-8507 and CVE-2024-1538 for nearby disclosures in the same product family.