PT-2024-15110 · WordPress · File Manager Pro

Kun_19

+1

·

Published

2024-02-05

·

Updated

2024-10-18

·

CVE-2023-6846

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions File Manager Pro plugin for WordPress versions up to, and including, 8.3.4
Description The issue allows authenticated attackers, with subscriber access and above, to execute code on the server via the mk check filemanager php syntax AJAX function. This enables arbitrary file upload. The vulnerability is exploited by authenticated users with sufficient access levels, making it possible to execute server-side code.
Recommendations For versions up to, and including, 8.3.4, update to version 8.3.5 or later, which introduces a capability check that prevents users lower than admin from executing the vulnerable function. As a temporary workaround, consider restricting access to the mk check filemanager php syntax AJAX function until a patch is available.

Exploit

Fix

Unrestricted File Upload

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2023-6846

Affected Products

File Manager Pro