WordPress File Manager Plugin Remote Code Execution Vulnerability
cve CVE-2020-25213 3 sources, 4 claims · Watch
CISA Known Exploited Vulnerabilities writes:
WordPress File Manager Plugin Remote Code Execution Vulnerability WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site. Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2020-25213 the claim
WordPress File Manager Plugin Remote Code Execution Vulnerability WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site. Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2020-25213 the claim
What each source says
| Property | Source | Said | Means here |
|---|---|---|---|
| Author author | Exploit-DB | BLYreceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "BLY",
"codes": "CVE-2020-25213",
"date_added": "2023-04-03",
"date_published": "2023-04-03",
"date_updated": "2023-05-24",
"description": "WP-file-manager v6.9 - Unauthenticated Arbitrary File Upload leading to RCE",
"file": "exploits/php/webapps/51224.py",
"id": "51224",
"platform": "php",
"port": "",
"screenshot_url": "",
"source_url": "",
"tags": "",
"type": "webapps",
"verified": "1"
} | — |
| Author author | Mansoor Rreceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Mansoor R",
"codes": "CVE-2020-25213",
"date_added": "2020-12-02",
"date_published": "2020-12-02",
"date_updated": "2021-03-18",
"description": "WordPress Plugin Wp-FileManager 6.8 - RCE",
"file": "exploits/php/webapps/49178.sh",
"id": "49178",
"platform": "php",
"port": "",
"screenshot_url": "",
"source_url": "",
"tags": "",
"type": "webapps",
"verified": "0"
} | — | |
| Cwes cwes | CISA Known Exploited Vulnerabilities | CWE-434receipt
What the source handed over{
"cveID": "CVE-2020-25213",
"cwes": "CWE-434",
"dateAdded": "2021-11-03",
"dueDate": "2022-05-03",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://nvd.nist.gov/vuln/detail/CVE-2020-25213",
"product": "File Manager Plugin",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site.",
"vendorProject": "WordPress",
"vulnerabilityName": "WordPress File Manager Plugin Remote Code Execution Vulnerability"
} | — |
| Due date due_date | CISA Known Exploited Vulnerabilities | 2022-05-03receipt
What the source handed over{
"cveID": "CVE-2020-25213",
"cwes": "CWE-434",
"dateAdded": "2021-11-03",
"dueDate": "2022-05-03",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://nvd.nist.gov/vuln/detail/CVE-2020-25213",
"product": "File Manager Plugin",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site.",
"vendorProject": "WordPress",
"vulnerabilityName": "WordPress File Manager Plugin Remote Code Execution Vulnerability"
} | — |
| Exploited exploited | CISA Known Exploited Vulnerabilities | yesreceipt
What the source handed over{
"cveID": "CVE-2020-25213",
"cwes": "CWE-434",
"dateAdded": "2021-11-03",
"dueDate": "2022-05-03",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://nvd.nist.gov/vuln/detail/CVE-2020-25213",
"product": "File Manager Plugin",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site.",
"vendorProject": "WordPress",
"vulnerabilityName": "WordPress File Manager Plugin Remote Code Execution Vulnerability"
} | — |
| Forensic triage forensic_triage | CISA Known Exploited Vulnerabilities | falsereceipt
What the source handed over{
"cveID": "CVE-2020-25213",
"cwes": "CWE-434",
"dateAdded": "2021-11-03",
"dueDate": "2022-05-03",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://nvd.nist.gov/vuln/detail/CVE-2020-25213",
"product": "File Manager Plugin",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site.",
"vendorProject": "WordPress",
"vulnerabilityName": "WordPress File Manager Plugin Remote Code Execution Vulnerability"
} | — |
| Known ransomware campaign use known_ransomware_campaign_use | CISA Known Exploited Vulnerabilities | Unknownreceipt
What the source handed over{
"cveID": "CVE-2020-25213",
"cwes": "CWE-434",
"dateAdded": "2021-11-03",
"dueDate": "2022-05-03",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://nvd.nist.gov/vuln/detail/CVE-2020-25213",
"product": "File Manager Plugin",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site.",
"vendorProject": "WordPress",
"vulnerabilityName": "WordPress File Manager Plugin Remote Code Execution Vulnerability"
} | — |
| Platform platform not compared | Exploit-DB | phpreceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Mansoor R",
"codes": "CVE-2020-25213",
"date_added": "2020-12-02",
"date_published": "2020-12-02",
"date_updated": "2021-03-18",
"description": "WordPress Plugin Wp-FileManager 6.8 - RCE",
"file": "exploits/php/webapps/49178.sh",
"id": "49178",
"platform": "php",
"port": "",
"screenshot_url": "",
"source_url": "",
"tags": "",
"type": "webapps",
"verified": "0"
} | — |
| Platform platform not compared | Metasploit exploit modules | PHPreceipt
What the source handed over{
"aliases": [],
"arch": "php",
"author": [
"Alex Souza (w4fz5uck5)",
"Imran E. Dawoodjee <imran@threathounds.com>"
],
"autofilter_ports": [
80,
8080,
443,
8000,
8888,
8880,
8008,
3000,
8443
],
"autofilter_services": [
"http",
"https"
],
"check": true,
"default_credential": false,
"description": "The File Manager (wp-file-manager) plugin from 6.0 to 6.8 for WordPress allows remote attackers to upload and\n execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php\n extension. This, for example, allows attackers to run the elFinder upload (or mkfile and put) command to write\n PHP code into the wp-content/plugins/wp-file-manager/lib/files/ directory.",
"disclosure_date": "2020-09-09",
"fullname": "exploit/multi/http/wp_file_manager_rce",
"is_install_path": true,
"mod_time": "2026-04-22 11:58:04 +0000",
"name": "WordPress File Manager Unauthenticated Remote Code Execution",
"needs_cleanup": true,
"notes": {
"Reliability": [
"repeatable-session"
],
"SideEffects": [
"artifacts-on-disk",
"ioc-in-logs"
],
"Stability": [
"crash-safe"
]
},
"path": "/modules/exploits/multi/http/wp_file_manager_rce.rb",
"platform": "PHP",
"post_auth": false,
"rank": 300,
"ref_name": "multi/http/wp_file_manager_rce",
"references": [
"URL-https://github.com/w4fz5uck5/wp-file-manager-0day",
"URL-https://www.tenable.com/cve/CVE-2020-25213",
"CVE-2020-25213"
],
"rport": 80,
"session_types": false,
"targets": [
"WordPress File Manager 6.0-6.8"
],
"type": "exploit"
} | — |
| Product product | CISA Known Exploited Vulnerabilities | File Manager Pluginreceipt
What the source handed over{
"cveID": "CVE-2020-25213",
"cwes": "CWE-434",
"dateAdded": "2021-11-03",
"dueDate": "2022-05-03",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://nvd.nist.gov/vuln/detail/CVE-2020-25213",
"product": "File Manager Plugin",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site.",
"vendorProject": "WordPress",
"vulnerabilityName": "WordPress File Manager Plugin Remote Code Execution Vulnerability"
} | — |
| Rank rank | Metasploit exploit modules | 300 Normal. Reliable against a version range the module detects. receipt
What the source handed over{
"aliases": [],
"arch": "php",
"author": [
"Alex Souza (w4fz5uck5)",
"Imran E. Dawoodjee <imran@threathounds.com>"
],
"autofilter_ports": [
80,
8080,
443,
8000,
8888,
8880,
8008,
3000,
8443
],
"autofilter_services": [
"http",
"https"
],
"check": true,
"default_credential": false,
"description": "The File Manager (wp-file-manager) plugin from 6.0 to 6.8 for WordPress allows remote attackers to upload and\n execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php\n extension. This, for example, allows attackers to run the elFinder upload (or mkfile and put) command to write\n PHP code into the wp-content/plugins/wp-file-manager/lib/files/ directory.",
"disclosure_date": "2020-09-09",
"fullname": "exploit/multi/http/wp_file_manager_rce",
"is_install_path": true,
"mod_time": "2026-04-22 11:58:04 +0000",
"name": "WordPress File Manager Unauthenticated Remote Code Execution",
"needs_cleanup": true,
"notes": {
"Reliability": [
"repeatable-session"
],
"SideEffects": [
"artifacts-on-disk",
"ioc-in-logs"
],
"Stability": [
"crash-safe"
]
},
"path": "/modules/exploits/multi/http/wp_file_manager_rce.rb",
"platform": "PHP",
"post_auth": false,
"rank": 300,
"ref_name": "multi/http/wp_file_manager_rce",
"references": [
"URL-https://github.com/w4fz5uck5/wp-file-manager-0day",
"URL-https://www.tenable.com/cve/CVE-2020-25213",
"CVE-2020-25213"
],
"rport": 80,
"session_types": false,
"targets": [
"WordPress File Manager 6.0-6.8"
],
"type": "exploit"
} | — |
| Type type | Exploit-DB | webappsreceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Mansoor R",
"codes": "CVE-2020-25213",
"date_added": "2020-12-02",
"date_published": "2020-12-02",
"date_updated": "2021-03-18",
"description": "WordPress Plugin Wp-FileManager 6.8 - RCE",
"file": "exploits/php/webapps/49178.sh",
"id": "49178",
"platform": "php",
"port": "",
"screenshot_url": "",
"source_url": "",
"tags": "",
"type": "webapps",
"verified": "0"
} | — |
| Vendor project vendor_project | CISA Known Exploited Vulnerabilities | WordPressreceipt
What the source handed over{
"cveID": "CVE-2020-25213",
"cwes": "CWE-434",
"dateAdded": "2021-11-03",
"dueDate": "2022-05-03",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://nvd.nist.gov/vuln/detail/CVE-2020-25213",
"product": "File Manager Plugin",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site.",
"vendorProject": "WordPress",
"vulnerabilityName": "WordPress File Manager Plugin Remote Code Execution Vulnerability"
} | — |
| Verified verified | Exploit-DB | falsereceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Mansoor R",
"codes": "CVE-2020-25213",
"date_added": "2020-12-02",
"date_published": "2020-12-02",
"date_updated": "2021-03-18",
"description": "WordPress Plugin Wp-FileManager 6.8 - RCE",
"file": "exploits/php/webapps/49178.sh",
"id": "49178",
"platform": "php",
"port": "",
"screenshot_url": "",
"source_url": "",
"tags": "",
"type": "webapps",
"verified": "0"
} | — |
| Verified verified | truereceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "BLY",
"codes": "CVE-2020-25213",
"date_added": "2023-04-03",
"date_published": "2023-04-03",
"date_updated": "2023-05-24",
"description": "WP-file-manager v6.9 - Unauthenticated Arbitrary File Upload leading to RCE",
"file": "exploits/php/webapps/51224.py",
"id": "51224",
"platform": "php",
"port": "",
"screenshot_url": "",
"source_url": "",
"tags": "",
"type": "webapps",
"verified": "1"
} | — |
vulnerability
| WordPress File Manager Plugin Remote Code Execution Vulnerability zetlyn/cve-kev · 2021-11-03 | cwes CWE-434 due_date 2022-05-03 exploited yes forensic_triage false known_ransomware_campaign_use Unknown product File Manager Plugin vendor_project WordPress |
exploit
| WordPress File Manager Unauthenticated Remote Code Execution zetlyn/cve-metasploit · 2020-09-09 | platform PHP rank 300 | source |
| WordPress Plugin Wp-FileManager 6.8 - RCE zetlyn/cve-exploitdb · 2020-12-02 | author Mansoor R platform php type webapps verified false | source |
| WP-file-manager v6.9 - Unauthenticated Arbitrary File Upload leading to RCE zetlyn/cve-exploitdb · 2023-04-03 | author BLY platform php type webapps verified true | source |