CVE 6.5 MEDIUM

Multiple elFinder Plugins <= (Various Versions) - Directory Traversal to Arbitrary File Deletion_CVE-2025-0818

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L

Description

Several WordPress plugins using elFinder versions 2.1.64 and prior are vulnerable to Directory Traversal in various versions. This makes it possible for unauthenticated attackers to delete arbitrary files. Successful exploitation of this vulnerability requires a site owner to explicitly make an instance of the file manager available to users.

Basic Information

ID CVE-2025-0818
Source Wordfence
Published Aug 13, 2025 at 03:42
Modified Aug 13, 2025 at 14:01

Affected Product

Vendor ninjateam
Product File Manager Pro – Filester
Version *
Affected Versions ninjateam File Manager Pro – Filester *
saadiqbal Advanced File Manager – Ultimate WP File Manager And Document Library Solution *
mndpsingh287 File Manager *

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.