HomeWordPress vulnerabilitiesFile Manager
File Manager vulnerabilities
File Manager has 13 known vulnerabilities in this database. The most recent published record is dated 26 Sep 2026.
- Known vulnerabilities
- 13
- Active installs
- 1m+
- Latest version
- 8.0.6
- Last updated
- 24 Sep 2026
- Most recent
- 26 Sep 2026
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Sensitive data exposure CVE-2026-19708 | Medium 5.9 | Before 8.0.5 | Fixed in 8.0.5 | 11 d ago |
| Cross-site scripting (XSS) CVE-2026-85081 | High 7.5 | Before 8.0.5 | Fixed in 8.0.5 | 11 d ago |
| Denial of service CVE-2026-17540 | High 8.8 | Before 6.9.1 | Fixed in 6.9.1 | 10 Aug 2026 |
| Sensitive data exposure CVE-2026-17541 | High 7.5 | Before 6.9.1 | Fixed in 6.9.1 | 10 Aug 2026 |
| Sensitive data exposure CVE-2026-17542 | High 7.5 | Before 6.9.1 | Fixed in 6.9.1 | 10 Aug 2026 |
| Remote code execution CVE-2018-25105 | Critical 9.8 | Up to 3.0 | Fixed in a later version (latest 8.0.6) | 16 Oct 2024 |
| Path traversal CVE-2024-2654 | Medium 6.8 | Before 7.2.6 | Fixed in 7.2.6 | 9 Apr 2024 |
| Cross-site request forgery (CSRF) CVE-2024-1538 | High 8.8 | Before 7.2.5 | Fixed in 7.2.5 | 21 Mar 2024 |
| Sensitive data exposure CVE-2024-0761 | High 8.1 | Up to 7.2.1 | Fixed in a later version (latest 8.0.6) | 5 Feb 2024 |
| Security weakness CVE-2023-5907 | Medium 6.5 | Before 6.3 | Fixed in 6.3 | 11 Dec 2023 |
| Arbitrary file upload Exploited in the wild CVE-2020-25213 | Critical 10.0 | Before 6.9 | Fixed in 6.9 | 9 Sep 2020 |
| Cross-site request forgery (CSRF) CVE-2018-16966 | High 8.8 | Not yet published | Check for an update | 15 Apr 2019 |
| Cross-site scripting (XSS) CVE-2018-16967 | Medium 6.1 | Not yet published | Check for an update | 15 Apr 2019 |
Read the published descriptions
- CVE-2026-19708, 26 Sep 2026
- The File Manager WordPress plugin before 8.0.5 does not prevent unauthenticated users from downloading its database backup archives, and in some cases writes them under a fixed filename, allowing unauthenticated attackers to retrieve a full database dump including every user's email address and password hash on servers that do not apply the directory's .htaccess file. CVE record
- CVE-2026-85081, 26 Sep 2026
- The File Manager WordPress plugin before 8.0.5, FileOrganizer WordPress plugin before 1.2.1, File Manager Pro WordPress plugin before 2.1.3 do not correctly validate the origin of window messages received by the file browser they load on their admin screens, accepting any origin that is a leading string prefix of the site's own address, which allows an unauthenticated attacker to run arbitrary JavaScript in the session of a logged-in administrator who visits a page under their control. The defect is in the file-manager library all three bundle, and every version below 2.1.70 carries it. Updating the bundled library closes it. CVE record
- CVE-2026-17540, 10 Aug 2026
- The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a subscriber, to read and delete arbitrary files under the WordPress installation directory, which could lead to the disclosure of the site's configuration secrets and to denial of service. CVE record
- CVE-2026-17541, 10 Aug 2026
- The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to read its file activity log, disclosing the file operations performed on the site, the paths involved and the name of the user who performed them. CVE record
- CVE-2026-17542, 10 Aug 2026
- The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connector endpoints, allowing any authenticated user, such as a subscriber, to browse the entire WordPress installation directory and download files of certain types from it, including archives and documents which may contain sensitive data. CVE record
- CVE-2018-25105, 16 Oct 2024
- The File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the /inc/root.php file in versions up to, and including, 3.0. This makes it possible for unauthenticated attackers to download arbitrary files from the server and upload arbitrary files that can be used for remote code execution. CVE record
- CVE-2024-2654, 9 Apr 2024
- The File Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.2.5 via the fm_download_backup function. This makes it possible for authenticated attackers, with administrator access and above, to read the contents of arbitrary zip files on the server, which can contain sensitive information. CVE record
- CVE-2024-1538, 21 Mar 2024
- The File Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.4. This is due to missing or incorrect nonce validation on the wp_file_manager page that includes files through the 'lang' parameter. This makes it possible for unauthenticated attackers to include local JavaScript files that can be leveraged to achieve RCE via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This issue was partially patched in version 7.2.4, and fully patched in 7.2.5. CVE record
- CVE-2024-0761, 5 Feb 2024
- The File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.2.1 due to insufficient randomness in the backup filenames, which use a timestamp plus 4 random digits. This makes it possible for unauthenticated attackers, to extract sensitive data including site backups in configurations where the .htaccess file in the directory does not block access. CVE record
- CVE-2023-5907, 11 Dec 2023
- The File Manager WordPress plugin before 6.3 does not restrict the file managers root directory, allowing an administrator to set a root outside of the WordPress root directory, giving access to system files and directories even in a multisite setup, where site administrators should not be allowed to modify the sites files. CVE record
- CVE-2020-25213, 9 Sep 2020
- The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php extension. This, for example, allows attackers to run the elFinder upload (or mkfile and put) command to write PHP code into the wp-content/plugins/wp-file-manager/lib/files/ directory. This was exploited in the wild in August and September 2020. CVE record
- CVE-2018-16966, 15 Apr 2019
- There is a CSRF vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter. CVE record
- CVE-2018-16967, 15 Apr 2019
- There is an XSS vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter. CVE record
What to do if you run File Manager
If you run File Manager, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new File Manager vulnerabilities
Free. We email you when a new vulnerability is published for File Manager, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.