VYPR

Bit File Manager

by WordPress

CVEs (4)

  • CVE-2024-7770HigSep 10, 2024
    risk 0.57cvss 8.8epss 0.01

    The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload' function in all versions up to, and including, 6.5.5. This makes it…

  • CVE-2024-7627HigSep 5, 2024
    risk 0.46cvss 8.1epss 0.03

    The Bit File Manager plugin for WordPress is vulnerable to Remote Code Execution in versions 6.0 to 6.5.5 via the 'checkSyntax' function. This is due to writing a temporary file to a publicly accessible directory before performing file validation. This makes it possible for…

  • CVE-2025-1725MedJun 3, 2025
    risk 0.42cvss 6.4epss 0.00

    The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.7 due to insufficient input sanitization and output…

  • CVE-2024-8743MedOct 5, 2024
    risk 0.37cvss 6.8epss 0.01

    The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and including, 6.5.7. This is due to a lack of proper checks on allowed file types. This makes…