peter bassill · operator
$ cve CVE-2020-25213 JSON

CVE-2020-25213 KEV EXPLOIT

10.0
CRITICAL · CVSS 3.1 · EPSS 97.3% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-05-03.

Description

The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php extension. This, for example, allows attackers to run the elFinder upload (or mkfile and put) command to write PHP code into the wp-content/plugins/wp-file-manager/lib/files/ directory. This was exploited in the wild in August and September 2020.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS97.33% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-434
On CISA KEVyes — remediate by 2022-05-03
Public exploityes
Published2020-09-09
Last modified2026-06-17

CISA KEV

NameWordPress File Manager Plugin Remote Code Execution Vulnerability
Added2021-11-03
Due2022-05-03
Vendor / productWordPress / File Manager Plugin
Ransomware usenone reported

Affected (1)

VendorProduct
filemanagerprofile manager

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD