6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L
Description
Several WordPress plugins using elFinder versions 2.1.64 and prior are vulnerable to Directory Traversal in various versions. This makes it possible for unauthenticated attackers to delete arbitrary files. Successful exploitation of this vulnerability requires a site owner to explicitly make an instance of the file manager available to users.
Basic Information
ID
CVE-2025-0818
Source
Wordfence
Published
Aug 13, 2025 at 03:42
Modified
Aug 13, 2025 at 14:01
Affected Product
Vendor
ninjateam
Product
File Manager Pro – Filester
Version
*
Affected Versions
ninjateam File Manager Pro – Filester *
saadiqbal Advanced File Manager – Ultimate WP File Manager And Document Library Solution *
mndpsingh287 File Manager *
saadiqbal Advanced File Manager – Ultimate WP File Manager And Document Library Solution *
mndpsingh287 File Manager *
CWE Classification
References
- www.wordfence.com /threat-intel/vulnerabilities/id/c2a166de-3bdf-4883-91ba-655f2757c53b
- github.com /Studio-42/elFinder
- plugins.trac.wordpress.org /browser/wp-file-manager/trunk/lib/php/elFinder.class.php
- plugins.trac.wordpress.org /browser/file-manager-advanced/trunk/application/library/php/elFinder.class.php
- plugins.trac.wordpress.org /browser/filester/trunk/includes/File_manager/lib/php/elFinder.class.php
- github.com /Studio-42/elFinder/blob/master/php/elFinder.class.php
- plugins.trac.wordpress.org /changeset/3319016/filester
- plugins.trac.wordpress.org /changeset/3335715/file-manager-advanced/trunk/application/library/php/elFinder.class.php