Description
The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_install_plugin' function in all versions up to, and including, 1.8.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install the Filebird plugin.
Problem types
Product status
* (semver)
Timeline
| 2024-12-06: | Vendor Notified |
| 2024-12-18: | Disclosed |
Credits
Trương Hữu Phúc (truonghuuphuc)
References
www.wordfence.com/...-4d6e-4de0-b6ab-6ac27c4f2be6?source=cve
plugins.trac.wordpress.org/changeset/3208858/filester