/Vulnerability Library

WordPress File Manager <= 7.2.1 - Directory Traversal

CVE-2023-6825
Verified

Description

File Manager and File Manager Pro plugins for WordPress versions up to 7.2.1 and 8.3.4 contain a directory traversal caused by the 'target' parameter in mk_file_folder_manager_action_callback_shortcode, letting attackers read arbitrary files and upload files outside designated directories, exploit requires administrator privileges for free version and can be exploited by lower-level users in Pro version.

Severity

Critical

CVSS Score

9.9

Exploit Probability

6%

Affected Product

file-manager

Published Date

April 8, 2026

Template Author

pussycat0x

CVE-2023-6825.yaml
9.9Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
CVE ID:
cve-2023-6825
CWE ID:
cwe-22

References

https://www.wordfence.com/threat-intel/vulnerabilities/id/93f377a1-2c33-4dd7-8fd6-190d9148e804https://plugins.trac.wordpress.org/changeset/3023403

Remediation Steps

Update to the latest versions of the plugins, beyond 7.2.1 for free and 8.3.4 for Pro, or disable the plugins until patched.