PT-2024-21416 · WordPress · File Manager

Abdelnour Osman

+1

·

Published

2024-04-09

·

Updated

2025-09-29

·

CVE-2024-2654

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions File Manager plugin for WordPress versions up to, and including, 7.2.5
Description The issue allows authenticated attackers with administrator access and above to read the contents of arbitrary zip files on the server, which can contain sensitive information, via the fm download backup function.
Recommendations For versions up to, and including, 7.2.5, update to a version that fixes this issue to prevent exploitation. As a temporary workaround, consider restricting access to the fm download backup function until a patch is available.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-2654

Affected Products

File Manager