High severity8.8NVD Advisory· Published Oct 16, 2024· Updated Jun 17, 2026
CVE-2024-8507
CVE-2024-8507
Description
The File Manager Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.3.9. This is due to missing or incorrect nonce validation on the 'mk_file_folder_manager' ajax action. This makes it possible for unauthenticated attackers to upload arbitrary files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:a:filemanagerpro:file_manager:*:*:*:*:pro:wordpress:*:*Range: <8.3.10
- Range: <=8.3.9
- Range: <=8.3.9
- File Manager/File Manager Prov5Range: 0
Patches
Vulnerability mechanics
References
2- www.wordfence.com/threat-intel/vulnerabilities/id/db70b37c-707a-47b8-a3a2-5a2b7d30de89nvdThird Party Advisory
- filemanagerpro.ionvdProduct
News mentions
0No linked articles in our index yet.