WordPress File Manager Plugin Remote Code Execution Vulnerability

cve CVE-2020-25213 3 sources, 4 claims · Watch

CISA Known Exploited Vulnerabilities writes:
WordPress File Manager Plugin Remote Code Execution Vulnerability WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site. Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2020-25213 the claim

What each source says

PropertySourceSaidMeans here
Author
author
Exploit-DBBLY
receipt
Source
Exploit-DB
Its words
BLY
Read by
field:author
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "BLY",
  "codes": "CVE-2020-25213",
  "date_added": "2023-04-03",
  "date_published": "2023-04-03",
  "date_updated": "2023-05-24",
  "description": "WP-file-manager v6.9 - Unauthenticated Arbitrary File Upload leading to RCE",
  "file": "exploits/php/webapps/51224.py",
  "id": "51224",
  "platform": "php",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "webapps",
  "verified": "1"
}
—
Author
author
Mansoor R
receipt
Source
Exploit-DB
Its words
Mansoor R
Read by
field:author
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Mansoor R",
  "codes": "CVE-2020-25213",
  "date_added": "2020-12-02",
  "date_published": "2020-12-02",
  "date_updated": "2021-03-18",
  "description": "WordPress Plugin Wp-FileManager 6.8 - RCE",
  "file": "exploits/php/webapps/49178.sh",
  "id": "49178",
  "platform": "php",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "webapps",
  "verified": "0"
}
—
Cwes
cwes
CISA Known Exploited VulnerabilitiesCWE-434
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
CWE-434
Read by
field:cwes
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 18:00 UTC
What the source handed over
{
  "cveID": "CVE-2020-25213",
  "cwes": "CWE-434",
  "dateAdded": "2021-11-03",
  "dueDate": "2022-05-03",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://nvd.nist.gov/vuln/detail/CVE-2020-25213",
  "product": "File Manager Plugin",
  "requiredAction": "Apply updates per vendor instructions.",
  "shortDescription": "WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site.",
  "vendorProject": "WordPress",
  "vulnerabilityName": "WordPress File Manager Plugin Remote Code Execution Vulnerability"
}
—
Due date
due_date
CISA Known Exploited Vulnerabilities2022-05-03
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
2022-05-03
Read by
field:dueDate
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 18:00 UTC
What the source handed over
{
  "cveID": "CVE-2020-25213",
  "cwes": "CWE-434",
  "dateAdded": "2021-11-03",
  "dueDate": "2022-05-03",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://nvd.nist.gov/vuln/detail/CVE-2020-25213",
  "product": "File Manager Plugin",
  "requiredAction": "Apply updates per vendor instructions.",
  "shortDescription": "WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site.",
  "vendorProject": "WordPress",
  "vulnerabilityName": "WordPress File Manager Plugin Remote Code Execution Vulnerability"
}
—
Exploited
exploited
CISA Known Exploited Vulnerabilitiesyes
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
yes
Read by
const:yes
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 18:00 UTC
What the source handed over
{
  "cveID": "CVE-2020-25213",
  "cwes": "CWE-434",
  "dateAdded": "2021-11-03",
  "dueDate": "2022-05-03",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://nvd.nist.gov/vuln/detail/CVE-2020-25213",
  "product": "File Manager Plugin",
  "requiredAction": "Apply updates per vendor instructions.",
  "shortDescription": "WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site.",
  "vendorProject": "WordPress",
  "vulnerabilityName": "WordPress File Manager Plugin Remote Code Execution Vulnerability"
}
—
Forensic triage
forensic_triage
CISA Known Exploited Vulnerabilitiesfalse
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
No
Read by
field:forensicTriage
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 18:00 UTC
What the source handed over
{
  "cveID": "CVE-2020-25213",
  "cwes": "CWE-434",
  "dateAdded": "2021-11-03",
  "dueDate": "2022-05-03",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://nvd.nist.gov/vuln/detail/CVE-2020-25213",
  "product": "File Manager Plugin",
  "requiredAction": "Apply updates per vendor instructions.",
  "shortDescription": "WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site.",
  "vendorProject": "WordPress",
  "vulnerabilityName": "WordPress File Manager Plugin Remote Code Execution Vulnerability"
}
—
Known ransomware campaign use
known_ransomware_campaign_use
CISA Known Exploited VulnerabilitiesUnknown
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Unknown
Read by
field:knownRansomwareCampaignUse
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 18:00 UTC
What the source handed over
{
  "cveID": "CVE-2020-25213",
  "cwes": "CWE-434",
  "dateAdded": "2021-11-03",
  "dueDate": "2022-05-03",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://nvd.nist.gov/vuln/detail/CVE-2020-25213",
  "product": "File Manager Plugin",
  "requiredAction": "Apply updates per vendor instructions.",
  "shortDescription": "WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site.",
  "vendorProject": "WordPress",
  "vulnerabilityName": "WordPress File Manager Plugin Remote Code Execution Vulnerability"
}
—
Platform
platform
not compared
Exploit-DBphp
receipt
Source
Exploit-DB
Its words
php
Read by
field:platform
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Mansoor R",
  "codes": "CVE-2020-25213",
  "date_added": "2020-12-02",
  "date_published": "2020-12-02",
  "date_updated": "2021-03-18",
  "description": "WordPress Plugin Wp-FileManager 6.8 - RCE",
  "file": "exploits/php/webapps/49178.sh",
  "id": "49178",
  "platform": "php",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "webapps",
  "verified": "0"
}
—
Platform
platform
not compared
Metasploit exploit modulesPHP
receipt
Source
Metasploit exploit modules
Its words
PHP
Read by
field:platform
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 17:59 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "php",
  "author": [
    "Alex Souza (w4fz5uck5)",
    "Imran E. Dawoodjee <imran@threathounds.com>"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": true,
  "default_credential": false,
  "description": "The File Manager (wp-file-manager) plugin from 6.0 to 6.8 for WordPress allows remote attackers to upload and\n          execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php\n          extension. This, for example, allows attackers to run the elFinder upload (or mkfile and put) command to write\n          PHP code into the wp-content/plugins/wp-file-manager/lib/files/ directory.",
  "disclosure_date": "2020-09-09",
  "fullname": "exploit/multi/http/wp_file_manager_rce",
  "is_install_path": true,
  "mod_time": "2026-04-22 11:58:04 +0000",
  "name": "WordPress File Manager Unauthenticated Remote Code Execution",
  "needs_cleanup": true,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "artifacts-on-disk",
      "ioc-in-logs"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/multi/http/wp_file_manager_rce.rb",
  "platform": "PHP",
  "post_auth": false,
  "rank": 300,
  "ref_name": "multi/http/wp_file_manager_rce",
  "references": [
    "URL-https://github.com/w4fz5uck5/wp-file-manager-0day",
    "URL-https://www.tenable.com/cve/CVE-2020-25213",
    "CVE-2020-25213"
  ],
  "rport": 80,
  "session_types": false,
  "targets": [
    "WordPress File Manager 6.0-6.8"
  ],
  "type": "exploit"
}
—
Product
product
CISA Known Exploited VulnerabilitiesFile Manager Plugin
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
File Manager Plugin
Read by
field:product
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 18:00 UTC
What the source handed over
{
  "cveID": "CVE-2020-25213",
  "cwes": "CWE-434",
  "dateAdded": "2021-11-03",
  "dueDate": "2022-05-03",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://nvd.nist.gov/vuln/detail/CVE-2020-25213",
  "product": "File Manager Plugin",
  "requiredAction": "Apply updates per vendor instructions.",
  "shortDescription": "WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site.",
  "vendorProject": "WordPress",
  "vulnerabilityName": "WordPress File Manager Plugin Remote Code Execution Vulnerability"
}
—
Rank
rank
Metasploit exploit modules300
Normal. Reliable against a version range the module detects.
receipt
Source
Metasploit exploit modules
Its words
300
Read by
field:rank
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 17:59 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "php",
  "author": [
    "Alex Souza (w4fz5uck5)",
    "Imran E. Dawoodjee <imran@threathounds.com>"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": true,
  "default_credential": false,
  "description": "The File Manager (wp-file-manager) plugin from 6.0 to 6.8 for WordPress allows remote attackers to upload and\n          execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php\n          extension. This, for example, allows attackers to run the elFinder upload (or mkfile and put) command to write\n          PHP code into the wp-content/plugins/wp-file-manager/lib/files/ directory.",
  "disclosure_date": "2020-09-09",
  "fullname": "exploit/multi/http/wp_file_manager_rce",
  "is_install_path": true,
  "mod_time": "2026-04-22 11:58:04 +0000",
  "name": "WordPress File Manager Unauthenticated Remote Code Execution",
  "needs_cleanup": true,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "artifacts-on-disk",
      "ioc-in-logs"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/multi/http/wp_file_manager_rce.rb",
  "platform": "PHP",
  "post_auth": false,
  "rank": 300,
  "ref_name": "multi/http/wp_file_manager_rce",
  "references": [
    "URL-https://github.com/w4fz5uck5/wp-file-manager-0day",
    "URL-https://www.tenable.com/cve/CVE-2020-25213",
    "CVE-2020-25213"
  ],
  "rport": 80,
  "session_types": false,
  "targets": [
    "WordPress File Manager 6.0-6.8"
  ],
  "type": "exploit"
}
—
Type
type
Exploit-DBwebapps
receipt
Source
Exploit-DB
Its words
webapps
Read by
field:type
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Mansoor R",
  "codes": "CVE-2020-25213",
  "date_added": "2020-12-02",
  "date_published": "2020-12-02",
  "date_updated": "2021-03-18",
  "description": "WordPress Plugin Wp-FileManager 6.8 - RCE",
  "file": "exploits/php/webapps/49178.sh",
  "id": "49178",
  "platform": "php",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "webapps",
  "verified": "0"
}
—
Vendor project
vendor_project
CISA Known Exploited VulnerabilitiesWordPress
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
WordPress
Read by
field:vendorProject
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 18:00 UTC
What the source handed over
{
  "cveID": "CVE-2020-25213",
  "cwes": "CWE-434",
  "dateAdded": "2021-11-03",
  "dueDate": "2022-05-03",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://nvd.nist.gov/vuln/detail/CVE-2020-25213",
  "product": "File Manager Plugin",
  "requiredAction": "Apply updates per vendor instructions.",
  "shortDescription": "WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site.",
  "vendorProject": "WordPress",
  "vulnerabilityName": "WordPress File Manager Plugin Remote Code Execution Vulnerability"
}
—
Verified
verified
Exploit-DBfalse
receipt
Source
Exploit-DB
Its words
0
Read by
field:verified
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Mansoor R",
  "codes": "CVE-2020-25213",
  "date_added": "2020-12-02",
  "date_published": "2020-12-02",
  "date_updated": "2021-03-18",
  "description": "WordPress Plugin Wp-FileManager 6.8 - RCE",
  "file": "exploits/php/webapps/49178.sh",
  "id": "49178",
  "platform": "php",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "webapps",
  "verified": "0"
}
—
Verified
verified
true
receipt
Source
Exploit-DB
Its words
1
Read by
field:verified
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "BLY",
  "codes": "CVE-2020-25213",
  "date_added": "2023-04-03",
  "date_published": "2023-04-03",
  "date_updated": "2023-05-24",
  "description": "WP-file-manager v6.9 - Unauthenticated Arbitrary File Upload leading to RCE",
  "file": "exploits/php/webapps/51224.py",
  "id": "51224",
  "platform": "php",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "webapps",
  "verified": "1"
}
—

vulnerability

WordPress File Manager Plugin Remote Code Execution Vulnerability
zetlyn/cve-kev · 2021-11-03
cwes CWE-434 due_date 2022-05-03 exploited yes forensic_triage false known_ransomware_campaign_use Unknown product File Manager Plugin vendor_project WordPress

exploit

WordPress File Manager Unauthenticated Remote Code Execution
zetlyn/cve-metasploit · 2020-09-09
platform PHP rank 300 source
WordPress Plugin Wp-FileManager 6.8 - RCE
zetlyn/cve-exploitdb · 2020-12-02
author Mansoor R platform php type webapps verified false source
WP-file-manager v6.9 - Unauthenticated Arbitrary File Upload leading to RCE
zetlyn/cve-exploitdb · 2023-04-03
author BLY platform php type webapps verified true source