CVE-2023-4861

CWE-94Code Injection3 documents3 sources
Severity
7.2HIGH
EPSS
3.9%
top 11.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 16

Description

The File Manager Pro WordPress plugin before 1.8.1 allows admin users to upload arbitrary files, even in environments where such a user should not be able to gain full control of the server, such as a multisite installation. This leads to remote code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages2 packages

NVDninjateam/filester< 1.8.1
CVEListV5unknown/file_manager_pro< 1.8.1

🔴Vulnerability Details

2
GHSA
GHSA-qmv3-76vc-754w: The File Manager Pro WordPress plugin before 12023-10-16
CVEList
File Manager Pro < 1.8.1 - Admin+ Remote Code Execution2023-10-16
CVE-2023-4861 (HIGH CVSS 7.2) | The File Manager Pro WordPress plug | cvebase.io