PT-2025-25457 · WordPress · File Manager Pro – Filester

Siunam

+1

·

Published

2025-06-14

·

Updated

2025-06-19

·

CVE-2025-3234

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions File Manager Pro – Filester plugin for WordPress versions 1.8.8 and earlier
Description The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server, which may make remote code execution possible. Administrators have the ability to extend file manager usage privileges to lower-level users, including subscribers, which would make this vulnerability more severe on such sites.
Recommendations For versions 1.8.8 and earlier, update to a version that includes the fix for this vulnerability. As a temporary workaround, consider restricting access to the file manager functionality to only necessary users until a patch is available. Restrict file uploads to only necessary file types to minimize the risk of exploitation.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-3234

Affected Products

File Manager Pro – Filester