Several WordPress plugins using elFinder versions 2.1.64 and prior are vulnerable to Directory Traversal in various versions. This makes it possible for unauthenticated attackers to delete arbitrary files. Successful exploitation of this vulnerability requires a site owner to explicitly make an instance of the file manager available to users.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| File Manager Advanced Plugin | file-manager-advanced-plugin-cve-2025-0818 | Aug 13, 2025 | Aug 12, 2025 | |
| Filester Plugin | filester-plugin-cve-2025-0818 | Aug 13, 2025 | Aug 12, 2025 | |
| Wp File Manager Plugin | wp-file-manager-plugin-cve-2025-0818 | Aug 13, 2025 | Aug 12, 2025 | |
| Wp File Manager Pro Plugin | wp-file-manager-pro-plugin-cve-2025-0818 | Aug 14, 2025 | Aug 12, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub