High severity7.5NVD Advisory· Published Oct 16, 2024· Updated Jun 17, 2026
CVE-2024-8746
CVE-2024-8746
Description
The File Manager Pro plugin for WordPress is vulnerable to arbitrary backup file downloads and uploads due to missing file type validation via the 'mk_file_folder_manager_shortcode' ajax action in all versions up to, and including, 8.3.9. This makes it possible for unauthenticated attackers, if granted access to the File Manager by an administrator, to download and upload arbitrary backup files on the affected site's server which may make remote code execution possible.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:a:filemanagerpro:file_manager:*:*:*:*:pro:wordpress:*:*Range: <8.3.10
<=8.3.9+ 1 more
- (no CPE)range: <=8.3.9
- (no CPE)
- File Manager/File Manager Prov5Range: 0
Patches
Vulnerability mechanics
References
2- www.wordfence.com/threat-intel/vulnerabilities/id/88f1eb9a-f3bb-4b62-975f-a6cb95850966nvdThird Party Advisory
- filemanagerpro.ionvdProduct
News mentions
0No linked articles in our index yet.