HTTP: WordPress File Manager connector.minimal.php Improper Access Control

This signature detects attempts to exploit a known vulnerability against WordPress File Manager. A successful attack can lead to arbitrary code execution.

Extended Description

The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php extension. This, for example, allows attackers to run the elFinder upload (or mkfile and put) command to write PHP code into the wp-content/plugins/wp-file-manager/lib/files/ directory. This was exploited in the wild in August and September 2020.

Affected Products

Webdesi9 file_manager

Short Name
HTTP:PHP:WP-FM-IMPRPR-ACCS-CTRL
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Access CVE-2020-25213 Control File Improper Manager WordPress connector.minimal.php
Release Date
10/16/2020
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Webdesi9

CVSS Score

7.5

Found a potential security threat?