CVE-2025-0818
Published: Aug 13, 2025
Modified: Apr 8, 2026
CVSS v3.1
6.5
Description
Several WordPress plugins using elFinder versions 2.1.64 and prior are vulnerable to Directory Traversal in various versions. This makes it possible for unauthenticated attackers to delete arbitrary files. Successful exploitation of this vulnerability requires a site owner to explicitly make an instance of the file manager available to users.
| Vendor | Product | Versions |
|---|---|---|
ninjateam | File Manager Pro – Filester | affected 0 - <= 1.8.9 |
saadiqbal | Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution | affected 0 - <= 5.3.6 |
File Manager | File Manager Pro | affected 0 - <= 8.4.2 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now