PT-2025-27167 · WordPress · File Manager Plugin For Wordpress

·

CVE-2025-53260

·

Publicado

2025-06-27

·

Atualizado

2025-06-27

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: File Manager Plugin For Wordpress versions prior to 7.5
Description: The issue allows attackers to upload dangerous files, including web shells, to a web server, compromising its security. This is due to an Unrestricted Upload of File with Dangerous Type vulnerability in the getredhawkstudio File Manager Plugin For Wordpress.
Recommendations: For versions prior to 7.5, update to version 7.5 to fix the issue. As a temporary workaround, consider restricting file upload capabilities to prevent the upload of dangerous file types until the update can be applied.

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-53260

Produtos afetados

File Manager Plugin For Wordpress