The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing validation in the 'fsConnector' function in all versions up to, and including, 1.8.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissions by an Administrator, to upload a new .htaccess file allowing them to subsequently upload arbitrary files on the affected site's server which may make remote code execution possible.
Metrics
Affected Vendors & Products
References
History
Wed, 26 Feb 2025 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Ninjateam filester
|
|
CPEs | cpe:2.3:a:ninjateam:filester:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Ninjateam filester
|
Sat, 04 Jan 2025 01:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing validation in the 'fsConnector' function in all versions up to, and including, 1.8.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissions by an Administrator, to upload a new .htaccess file allowing them to subsequently upload arbitrary files on the affected site's server which may make remote code execution possible. | The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing validation in the 'fsConnector' function in all versions up to, and including, 1.8.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissions by an Administrator, to upload a new .htaccess file allowing them to subsequently upload arbitrary files on the affected site's server which may make remote code execution possible. |
Title | File Manager Pro – Filester <= 1.8.4 - Authenticated (Subscriber+) Arbitrary File Upload | File Manager Pro – Filester <= 1.8.6- Authenticated (Subscriber+) Arbitrary File Upload |
Fri, 29 Nov 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Ninjateam
Ninjateam filemanager Pro-filester |
|
CPEs | cpe:2.3:a:ninjateam:filemanager_pro-filester:*:*:*:*:*:*:*:* | |
Vendors & Products |
Ninjateam
Ninjateam filemanager Pro-filester |
|
Metrics |
ssvc
|
Thu, 28 Nov 2024 09:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing validation in the 'fsConnector' function in all versions up to, and including, 1.8.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissions by an Administrator, to upload a new .htaccess file allowing them to subsequently upload arbitrary files on the affected site's server which may make remote code execution possible. | |
Title | File Manager Pro – Filester <= 1.8.4 - Authenticated (Subscriber+) Arbitrary File Upload | |
Weaknesses | CWE-434 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-01-06T17:45:20.183Z
Reserved: 2024-08-21T22:44:39.513Z
Link: CVE-2024-8066

Updated: 2024-11-29T15:29:49.339Z

Status : Analyzed
Published: 2024-11-28T09:15:05.547
Modified: 2025-02-26T19:54:38.100
Link: CVE-2024-8066

No data.