Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesFile Manager

File Manager vulnerabilities

File Manager has 9 known vulnerabilities in this database. The most recent published record is dated 6 Aug 2026.

Known vulnerabilities
9
Active installs
10,000+
Latest version
6.9.2
Last updated
2 Sep 2026
Most recent
6 Aug 2026

No fixed version has been published yet, so consider disabling, removing or replacing the plugin until a safe release is available.

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Remote code execution
CVE-2026-15991
High 8.8Not yet publishedCheck for an update6 Aug 2026
Cross-site scripting (XSS)
CVE-2025-1725
Medium 6.4Up to 6.7Fixed in a later version (latest 6.9.2)3 Jun 2025
Remote code execution
CVE-2024-7770
High 8.8Before 6.5.6Fixed in 6.5.610 Sep 2024
Remote code execution
CVE-2024-7627
High 8.1Before 6.5.6Fixed in 6.5.65 Sep 2024
Path traversal
CVE-2023-6825
Critical 9.9Up to 8.3.4No fixed version yet13 Mar 2024
PHP object injection
CVE-2022-47599
Medium 5.5Before 6.0.0Fixed in 6.0.020 Dec 2023
Cross-site scripting (XSS)
CVE-2021-24177
Medium 5.4Before 7.1Fixed in 7.15 Apr 2021
Cross-site scripting (XSS)
CVE-2018-16363
Medium 5.4Not yet publishedCheck for an update7 Sep 2018
Security weakness
CVE-2018-7204
High 7.5Up to 5.0.0Fixed in a later version (latest 6.9.2)7 Mar 2018
Read the published descriptions
CVE-2026-15991, 6 Aug 2026
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to read and delete arbitrary files on the server, which can lead to remote code execution when the right file is deleted (such as wp-config.php). The bypass is triggered by passing cmd=rm or cmf=file in the URL query string of a POST request: elFinder's bind registration reads the command exclusively from $_POST and therefore never registers the rm.pre permission handler, while the dispatcher reads from the merged $_GET+$_POST superglobal and executes the rm or file command unchecked against a volume that defaults to ABSPATH. CVE record
CVE-2025-1725, 3 Jun 2025
The Bit File Manager - 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file. CVE record
CVE-2024-7770, 10 Sep 2024
The Bit File Manager - 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload' function in all versions up to, and including, 6.5.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted upload permissions by an administrator, to upload arbitrary files on the affected site's server which may make remote code execution possible. CVE record
CVE-2024-7627, 5 Sep 2024
The Bit File Manager plugin for WordPress is vulnerable to Remote Code Execution in versions 6.0 to 6.5.5 via the 'checkSyntax' function. This is due to writing a temporary file to a publicly accessible directory before performing file validation. This makes it possible for unauthenticated attackers to execute code on the server if an administrator has allowed Guest User read permissions. CVE record
CVE-2023-6825, 13 Mar 2024
The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and including version 7.2.1 (free version) and 8.3.4 (Pro version) via the target parameter in the mk_file_folder_manager_action_callback_shortcode function. This makes it possible for attackers to read the contents of arbitrary files on the server, which can contain sensitive information and to upload files into directories other than the intended directory for file uploads. The free version requires Administrator access for this vulnerability to be exploitable. The Pro version allows a file manager to be embedded via a shortcode and also allows admins to grant file handling privileges to other user levels, which could lead to this vulnerability being exploited by lower-level users. CVE record
CVE-2022-47599, 20 Dec 2023
Deserialization of Untrusted Data vulnerability in File Manager by Bit Form Team File Manager - 100% Free & Open Source File Manager Plugin for WordPress | Bit File Manager.This issue affects File Manager - 100% Free & Open Source File Manager Plugin for WordPress | Bit File Manager: from n/a through 5.2.7. CVE record
CVE-2021-24177, 5 Apr 2021
In the default configuration of the File Manager WordPress plugin before 7.1, a Reflected XSS can occur on the endpoint /wp-admin/admin.php?page=wp_file_manager_properties when a payload is submitted on the User-Agent parameter. The payload is then reflected back on the web application response. CVE record
CVE-2018-16363, 7 Sep 2018
The mndpsingh287 File Manager plugin V2.9 for WordPress has XSS via the lang parameter in a wp-admin/admin.php?page=wp_file_manager request because set_transient is used in file_folder_manager.php and there is an echo of lang in lib\wpfilemanager.php. CVE record
CVE-2018-7204, 7 Mar 2018
inc/logger.php in the Giribaz File Manager plugin before 5.0.2 for WordPress logged activity related to the plugin in /wp-content/uploads/file-manager/log.txt. If a user edits the wp-config.php file using this plugin, the wp-config.php contents get added to log.txt, which is not protected and contains database credentials, salts, etc. These files have been indexed by Google and a simple dork will find affected sites. CVE record

What to do if you run File Manager

If you run File Manager, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new File Manager vulnerabilities

Free. We email you when a new vulnerability is published for File Manager, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support