PT-2020-15677 · WordPress · Wp File Manager
Published
2020-08-26
·
Updated
2025-03-24
·
CVE-2020-24312
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WP File Manager versions 6.4 and lower
Description
The issue allows unauthenticated users to browse and download site backups, including full database backups, due to the lack of restriction on external access to the fm backups directory. This is because the .htaccess file is not properly configured to protect the directory.
Recommendations
For WP File Manager versions 6.4 and lower, consider adding a properly configured .htaccess file to the fm backups directory to restrict external access until a patch is available. As a temporary workaround, restrict access to the fm backups directory to minimize the risk of exploitation.
Exploit
Fix
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp File Manager