The File Manager WordPress plugin before 6.3 does not restrict the file managers root directory, allowing an administrator to set a root outside of the WordPress root directory, giving access to system files and directories even in a multisite setup, where site administrators should not be allowed to modify the sites files.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 27 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-05-27T14:42:08.040Z
Reserved: 2023-11-01T15:24:37.072Z
Link: CVE-2023-5907
Updated: 2024-08-02T08:14:24.643Z
Status : Modified
Published: 2023-12-11T20:15:07.263
Modified: 2025-05-27T15:15:31.587
Link: CVE-2023-5907
No data.
OpenCVE Enrichment
No data.
Weaknesses