⚠ Actively exploited
Added to CISA KEV on 2021-11-03. Federal agencies required to patch by 2022-05-03. Required action: Apply updates per vendor instructions..

CVE-2020-25213Unrestricted File Upload in File Manager

Severity
9.8CRITICALNVD
CNA10.0VulnCheck10.0
EPSS
94.4%
top 0.02%
CISA KEV
KEV
Added 2021-11-03
Due 2022-05-03
Exploit
Exploited in wild
Active exploitation observed
Affected products
Timeline
PublishedSep 9
KEV addedNov 3
KEV dueMay 3
Latest updateApr 3
CISA Required Action: Apply updates per vendor instructions.

Description

The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php extension. This, for example, allows attackers to run the elFinder upload (or mkfile and put) command to write PHP code into the wp-content/plugins/wp-file-manager/lib/files/ directory. This was exploited in the wild in August and September 2020.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-w774-7g7w-83fx: The File Manager (wp-file-manager) plugin before 62022-05-24
CVEList
CVE-2020-25213: The File Manager (wp-file-manager) plugin before 62020-09-09
VulnCheck
WordPress File Manager Plugin Remote Code Execution Vulnerability2020

💥Exploits & PoCs

3
Exploit-DB
WP-file-manager v6.9 - Unauthenticated Arbitrary File Upload leading to RCE2023-04-03
Exploit-DB
WordPress Plugin Wp-FileManager 6.8 - RCE2020-12-02
Nuclei
WordPress File Manager Plugin - Remote Code Execution

📋Vendor Advisories

1
CISA
WordPress File Manager Plugin Remote Code Execution Vulnerability2021-11-03

🕵️Threat Intelligence

3
Unit42
Exploits in the Wild for WordPress File Manager RCE Vulnerability (CVE-2020-25213)2021-02-05
Unit42
Exploits in the Wild for WordPress File Manager RCE Vulnerability (CVE-2020-25213)2021-02-05
Unit42
Network Attack Trends: Internet of Threats (August-October 2020)2021-01-22
CVE-2020-25213 — Unrestricted File Upload | cvebase