WordPress File Manager <= 7.2.1 - Directory Traversal
CVE-2023-6825
Verified
Description
File Manager and File Manager Pro plugins for WordPress versions up to 7.2.1 and 8.3.4 contain a directory traversal caused by the 'target' parameter in mk_file_folder_manager_action_callback_shortcode, letting attackers read arbitrary files and upload files outside designated directories, exploit requires administrator privileges for free version and can be exploited by lower-level users in Pro version.
Severity
Critical
CVSS Score
9.9
Exploit Probability
6%
Affected Product
file-manager
Published Date
April 8, 2026
Template Author
pussycat0x
CVE-2023-6825.yaml
9.9Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
CVE ID:
cve-2023-6825
CWE ID:
cwe-22
Remediation Steps
Update to the latest versions of the plugins, beyond 7.2.1 for free and 8.3.4 for Pro, or disable the plugins until patched.