Arbitrary file upload in File Manager - CVE-2020-25213
Published: September 2, 2020 / Updated: October 25, 2024
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to insufficient validation of file during file upload in wp-file-manager in the "lib/php/connector.minimal.php" and "lib/files/hardfork.php" files. A remote attacker can upload a malicious file and execute it on the server.
Note: The vulnerability is being actively exploited in the wild.
Affected software
How to mitigate CVE-2020-25213
Links to Public Exploits and PoC-codes
- Exploit #10670 - WP-file-manager v6.9 - Unauthenticated Arbitrary File Upload leading to RCE (October 25, 2024)
- Exploit #9420 - CVE-2020-25213 () (December 6, 2023)
- Exploit #9223 - Python-CVE-2020-25213 (Python Interactive Exploit for WP File Manager Vulnerability. The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example e (August 3, 2023)
- Exploit #8766 - Python-exploit-CVE-2020-25213 (Python exploit for RCE in Wordpress) (January 23, 2023)
- Exploit #7882 - CVE-2020-25213 () (May 24, 2022)
- Exploit #7743 - CVE-2020-25213-wordpress-wp-file-manager-fileupload (WordPress的文件管理器插件(wp-file-manager)6.9版本之前存在安全漏洞,该漏洞允许远程攻击者上传和执行任意PHP代码。) (May 11, 2022)
- Exploit #5214 - Wordpress-CVE-2020-25213 (Will write a python script for exploiting this vulnerability ) (March 14, 2021)
- Exploit #5037 - 0day-elFinder-2020 (Zero-Day Vulnerability in File Manager Plugin 6.7 ( CVE 2020-25213 )) (January 18, 2021)
- Exploit #4851 - WPKiller (CVE-2020-25213 Wordpress File Manager 6.7 Plugin 0day exploit) (November 17, 2020)
- Exploit #4816 - WordPress File Manager Unauthenticated Remote Code Execution (November 10, 2020)
- Exploit #4698 - wp-file-manager-CVE-2020-25213 (https://medium.com/@mansoorr/exploiting-cve-2020-25213-wp-file-manager-wordpress-plugin-6-9-3f79241f0cd8) (October 14, 2020)