8.3.4 – Authenticated (Subscriber+) Arbitrary File Upload
-
The File Manager Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.3.4 via the mk_check_filemanager_php_syntax AJAX function. This makes it possible for authenticated attackers, with subscriber access and above, to execute code on the server. Version 8.3.5 introduces a capability check that prevents users lower than admin from executing this function.
https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-file-manager-pro/file-manager-pro-834-authenticated-subscriber-arbitrary-file-uploadThe page I need help with: [log in to see the link]
Viewing 6 replies - 1 through 6 (of 6 total)
Viewing 6 replies - 1 through 6 (of 6 total)
- The topic ‘8.3.4 – Authenticated (Subscriber+) Arbitrary File Upload’ is closed to new replies.