EXPOSURES › CVE-2020-25213
CVE-2020-25213
HIGH ⌖ ON CISA KEV · EXPLOITEDUnauthenticated attackers could execute arbitrary PHP code and upload malicious files via the WordPress File Manager Plugin.
The WordPress File Manager Plugin allowed unauthenticated remote code execution and file uploads, enabling attackers to compromise WordPress sites. DIB organizations must ensure all third-party plugins are patched and monitored, as unpatched vulnerabilities in widely used components are frequently exploited in the wild.
Shame score — A critical RCE vulnerability in a popular plugin was left unpatched long enough to be added to CISA's KEV catalog, indicating negligent patch management and avoidable exposure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site.
"WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site."