Skip to content
COOEY

EXPOSURES › CVE-2020-25213

CVE-2020-25213

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-25213 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

Unauthenticated attackers could execute arbitrary PHP code and upload malicious files via the WordPress File Manager Plugin.

The WordPress File Manager Plugin allowed unauthenticated remote code execution and file uploads, enabling attackers to compromise WordPress sites. DIB organizations must ensure all third-party plugins are patched and monitored, as unpatched vulnerabilities in widely used components are frequently exploited in the wild.

Shame score — A critical RCE vulnerability in a popular plugin was left unpatched long enough to be added to CISA's KEV catalog, indicating negligent patch management and avoidable exposure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
WordPress faced severe criticism for a critical RCE vulnerability in its File Manager plugin, allowing unauthenticated attackers to execute code and upload malicious files, highlighting significant se
cooey ↗ severe-fallout -0.60
WordPress was criticized for a critical RCE vulnerability in its File Manager plugin, allowing unauthenticated attackers to execute code and upload malicious files, highlighting significant security f
"WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site."
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.