Description
The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.8 via the ajax_downloadfile() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform actions on files outside of the originally intended directory.
Problem types
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
*
Timeline
2025-08-23: | Vendor Notified |
2025-08-27: | Disclosed |
Credits
Đỗ Quang Huy
References
www.wordfence.com/...-3136-4a1d-bbbd-ff484f1df5c3?source=cve
plugins.trac.wordpress.org/...-manager&sfp_email=&sfph_mail=