PT-2025-40060 · WordPress · File Manager

Aurélien Bourdois

·

Published

2025-10-01

·

Updated

2025-10-01

·

CVE-2025-10744

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions The File Manager, Code Editor, and Backup by Managefy plugin for WordPress versions prior to 1.6.2
Description The plugin is susceptible to a sensitive information exposure issue due to publicly exposed log files. This allows unauthenticated attackers to view information such as full paths and full paths to backup files contained within these logs.
Recommendations Update to version 1.6.2 or later.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-10744

Affected Products

File Manager