All vulnerabilities
CVE-2020-25213
WordPress File Manager Plugin Remote Code Execution Vulnerability
WordPress — File Manager Plugin
- Added to KEV catalog
- 3 November 2021
- Federal remediation due date
- 3 May 2022
- Weakness classification (CWE)
- CWE-434
CISA Description
WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site.
Required action
Apply updates per vendor instructions.
Notes
https://nvd.nist.gov/vuln/detail/CVE-2020-25213
More WordPress Vulnerabilities
Confirm Your Exposure
Is this vulnerability present in your environment?
CRS delivers independent VAPT assessments that identify exactly which known-exploited vulnerabilities exist in your network, applications, and infrastructure.
Explore VAPT Services