WordPress Plugin Vulnerabilities
Secure File Manager <= 2.9.3 - Admin+ RCE
Description
By default an user with administrator privileges can't upload php files for security reason, however, this can be bypassed just by renaming the file after the upload, leading to RCE. Note that this plugin could be accessed either by low-authenticated users if set in the options.
Proof of Concept
Affects Plugins
Miscellaneous
Original Researcher
Davide Taraschi
Submitter
Davide Taraschi
Submitter website
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2021-09-01 (about 4 years ago)
Added
2022-02-15 (about 4 years ago)
Last Updated
2022-02-15 (about 4 years ago)