CVE-2020-25213
WordPress File Manager Plugin Remote Code Execution Vulnerability
9.8
CVSS 3.1
97.3 %
EPSS (current)
2021-11-03
KEV addition
No
Ransomware
Timeline
Publication, first public exploit and KEV addition on a day axis.
Key facts
Vendor / product: WordPress / File Manager Plugin
Published: 2020-09-09 · Due (CISA): 2022-05-03
CWE: CWE-434 · EU list: no
Exploit references (metadata only)
| Source | Reference | Title | Date |
|---|---|---|---|
| nuclei | http/cves/2020/CVE-2020-25213.yaml | WordPress File Manager Plugin - Remote Code Execution | – |
| metasploit | exploit/multi/http/wp_file_manager_rce | exploit/multi/http/wp_file_manager_rce | 2020-09-09 |
| exploitdb | 49178 | WordPress Plugin Wp-FileManager 6.8 - RCE | 2020-12-02 |
| exploitdb | 51224 | WP-file-manager v6.9 - Unauthenticated Arbitrary File Upload leading to RCE | 2023-04-03 |
References only — no downloads or instructions.