HomeWordPress vulnerabilitiesFile Manager
File Manager vulnerabilities
File Manager has 9 known vulnerabilities in this database. The most recent published record is dated 6 Aug 2026.
- Known vulnerabilities
- 9
- Active installs
- 10,000+
- Latest version
- 6.9.2
- Last updated
- 2 Sep 2026
- Most recent
- 6 Aug 2026
No fixed version has been published yet, so consider disabling, removing or replacing the plugin until a safe release is available.
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Remote code execution CVE-2026-15991 | High 8.8 | Not yet published | Check for an update | 6 Aug 2026 |
| Cross-site scripting (XSS) CVE-2025-1725 | Medium 6.4 | Up to 6.7 | Fixed in a later version (latest 6.9.2) | 3 Jun 2025 |
| Remote code execution CVE-2024-7770 | High 8.8 | Before 6.5.6 | Fixed in 6.5.6 | 10 Sep 2024 |
| Remote code execution CVE-2024-7627 | High 8.1 | Before 6.5.6 | Fixed in 6.5.6 | 5 Sep 2024 |
| Path traversal CVE-2023-6825 | Critical 9.9 | Up to 8.3.4 | No fixed version yet | 13 Mar 2024 |
| PHP object injection CVE-2022-47599 | Medium 5.5 | Before 6.0.0 | Fixed in 6.0.0 | 20 Dec 2023 |
| Cross-site scripting (XSS) CVE-2021-24177 | Medium 5.4 | Before 7.1 | Fixed in 7.1 | 5 Apr 2021 |
| Cross-site scripting (XSS) CVE-2018-16363 | Medium 5.4 | Not yet published | Check for an update | 7 Sep 2018 |
| Security weakness CVE-2018-7204 | High 7.5 | Up to 5.0.0 | Fixed in a later version (latest 6.9.2) | 7 Mar 2018 |
Read the published descriptions
- CVE-2026-15991, 6 Aug 2026
- The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to read and delete arbitrary files on the server, which can lead to remote code execution when the right file is deleted (such as wp-config.php). The bypass is triggered by passing cmd=rm or cmf=file in the URL query string of a POST request: elFinder's bind registration reads the command exclusively from $_POST and therefore never registers the rm.pre permission handler, while the dispatcher reads from the merged $_GET+$_POST superglobal and executes the rm or file command unchecked against a volume that defaults to ABSPATH. CVE record
- CVE-2025-1725, 3 Jun 2025
- The Bit File Manager - 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file. CVE record
- CVE-2024-7770, 10 Sep 2024
- The Bit File Manager - 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload' function in all versions up to, and including, 6.5.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted upload permissions by an administrator, to upload arbitrary files on the affected site's server which may make remote code execution possible. CVE record
- CVE-2024-7627, 5 Sep 2024
- The Bit File Manager plugin for WordPress is vulnerable to Remote Code Execution in versions 6.0 to 6.5.5 via the 'checkSyntax' function. This is due to writing a temporary file to a publicly accessible directory before performing file validation. This makes it possible for unauthenticated attackers to execute code on the server if an administrator has allowed Guest User read permissions. CVE record
- CVE-2023-6825, 13 Mar 2024
- The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and including version 7.2.1 (free version) and 8.3.4 (Pro version) via the target parameter in the mk_file_folder_manager_action_callback_shortcode function. This makes it possible for attackers to read the contents of arbitrary files on the server, which can contain sensitive information and to upload files into directories other than the intended directory for file uploads. The free version requires Administrator access for this vulnerability to be exploitable. The Pro version allows a file manager to be embedded via a shortcode and also allows admins to grant file handling privileges to other user levels, which could lead to this vulnerability being exploited by lower-level users. CVE record
- CVE-2022-47599, 20 Dec 2023
- Deserialization of Untrusted Data vulnerability in File Manager by Bit Form Team File Manager - 100% Free & Open Source File Manager Plugin for WordPress | Bit File Manager.This issue affects File Manager - 100% Free & Open Source File Manager Plugin for WordPress | Bit File Manager: from n/a through 5.2.7. CVE record
- CVE-2021-24177, 5 Apr 2021
- In the default configuration of the File Manager WordPress plugin before 7.1, a Reflected XSS can occur on the endpoint /wp-admin/admin.php?page=wp_file_manager_properties when a payload is submitted on the User-Agent parameter. The payload is then reflected back on the web application response. CVE record
- CVE-2018-16363, 7 Sep 2018
- The mndpsingh287 File Manager plugin V2.9 for WordPress has XSS via the lang parameter in a wp-admin/admin.php?page=wp_file_manager request because set_transient is used in file_folder_manager.php and there is an echo of lang in lib\wpfilemanager.php. CVE record
- CVE-2018-7204, 7 Mar 2018
- inc/logger.php in the Giribaz File Manager plugin before 5.0.2 for WordPress logged activity related to the plugin in /wp-content/uploads/file-manager/log.txt. If a user edits the wp-config.php file using this plugin, the wp-config.php contents get added to log.txt, which is not protected and contains database credentials, salts, etc. These files have been indexed by Google and a simple dork will find affected sites. CVE record
What to do if you run File Manager
If you run File Manager, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new File Manager vulnerabilities
Free. We email you when a new vulnerability is published for File Manager, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.