CVE Database
/

CVE-2023-4827

Back to search

CVE-2023-4827

Published: Oct 16, 2023

Modified: Apr 23, 2025

PUBLISHED

Description

The File Manager Pro WordPress plugin before 1.8 does not properly check the CSRF nonce in the `fs_connector` AJAX action. This allows attackers to make highly privileged users perform unwanted file system actions via CSRF attacks by using GET requests, such as uploading a web shell.

VendorProductVersions

Unknown

File Manager Pro

affected
0 - < 1.8

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now