Several WordPress plugins using elFinder versions 2.1.64 and prior are vulnerable to Directory Traversal in various versions. This makes it possible for unauthenticated attackers to delete arbitrary files. Successful exploitation of this vulnerability requires a site owner to explicitly make an instance of the file manager available to users.
History

Thu, 14 Aug 2025 06:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Wed, 13 Aug 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 13 Aug 2025 04:00:00 +0000

Type Values Removed Values Added
Description Several WordPress plugins using elFinder versions 2.1.64 and prior are vulnerable to Directory Traversal in various versions. This makes it possible for unauthenticated attackers to delete arbitrary files. Successful exploitation of this vulnerability requires a site owner to explicitly make an instance of the file manager available to users.
Title Multiple elFinder Plugins <= (Various Versions) - Directory Traversal to Arbitrary File Deletion
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2025-08-13T03:42:04.514Z

Updated: 2025-08-13T14:01:52.795Z

Reserved: 2025-01-28T21:23:43.968Z

Link: CVE-2025-0818

cve-icon Vulnrichment

Updated: 2025-08-13T14:01:49.584Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-13T04:16:08.373

Modified: 2025-08-13T17:33:46.673

Link: CVE-2025-0818

cve-icon Redhat

No data.