S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2020-25213 Scanner

CVE-2020-25213 scanner - Unrestricted File Upload vulnerability in File Manager plugin for WordPress

Est. Time~30 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.5k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2020-25213
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php extension. This, for example, allows attackers to run the elFinder upload (or mkfile and put) command to write PHP code into the wp-content/plugins/wp-file-manager/lib/files/ directory. This was exploited in the wild in August and September 2020.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The File Manager plugin for WordPress is a popular tool used for managing files and directories on a website. It is designed to make file management easier and more efficient for website owners and administrators. With it, users can upload, delete, and modify files on their WordPress site directly from the admin dashboard. This plugin is highly regarded for its user-friendliness, versatility, and convenience.

Recently, however, a security flaw was detected in the plugin. The CVE-2020-25213 vulnerability allows remote attackers to execute arbitrary PHP code by exploiting the plugin's unsafe example elFinder connector file. Simply put, attackers can upload malicious software to the wp-content/plugins/wp-file-manager/lib/files/ directory via the elFinder command and potentially take control of the website in question.

If the vulnerability is exploited, attackers can gain access to sensitive data, modify website content, install and execute malware, and disrupt legitimate website functions. The consequences can be catastrophic, particularly for businesses that rely heavily on their website for revenue and customer engagement. Once a website is compromised, it can lose credibility, customers, and revenue in a matter of days.

Thanks to the pro features of s4e.io, website owners and administrators can quickly and easily identify and mitigate security risks on their WordPress website. The platform provides comprehensive vulnerability scanning, risk reporting, and remediation solutions that can help safeguard digital assets. By investing in the right security tools, website owners can take proactive steps to protect their online assets against cyber attacks.

 

REFERENCES

Solution Advice

To protect against the CVE-2020-25213 vulnerability in the File Manager plugin, website owners and administrators can take the following precautions:

  • Update to the latest version of the plugin.
  • Remove the unsafe elFinder connector file.
  • Restrict file uploads to authorized personnel only.
  • Enable server-side input validation and security measures.
  • Regularly scan the website for vulnerabilities using a reputable security tool.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-25213 scanner - Unrestricted File Upload vulnerability in File Manager plugin for WordPress | S4E