PT-2020-15677 · WordPress · Wp File Manager

Published

2020-08-26

·

Updated

2025-03-24

·

CVE-2020-24312

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WP File Manager versions 6.4 and lower
Description The issue allows unauthenticated users to browse and download site backups, including full database backups, due to the lack of restriction on external access to the fm backups directory. This is because the .htaccess file is not properly configured to protect the directory.
Recommendations For WP File Manager versions 6.4 and lower, consider adding a properly configured .htaccess file to the fm backups directory to restrict external access until a patch is available. As a temporary workaround, restrict access to the fm backups directory to minimize the risk of exploitation.

Exploit

Fix

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-24312

Affected Products

Wp File Manager