VYPR
Critical severity9.8NVD Advisory· Published Oct 16, 2024· Updated Jun 17, 2026No known patch

CVE-2018-25105

CVE-2018-25105

Description

The File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the /inc/root.php file in versions up to, and including, 3.0. This makes it possible for unauthenticated attackers to download arbitrary files from the server and upload arbitrary files that can be used for remote code execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:filemanagerpro:file_manager:*:*:*:*:*:wordpress:*:*+ 1 more
    • cpe:2.3:a:filemanagerpro:file_manager:*:*:*:*:*:wordpress:*:*range: <=3.0
    • (no CPE)range: 0
  • WordPress/File Managerllm-fuzzy2 versions
    <=3.0+ 1 more
    • (no CPE)range: <=3.0
    • (no CPE)

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.