Several WordPress plugins using elFinder versions 2.1.64 and prior are vulnerable to Directory Traversal in various versions. This makes it possible for unauthenticated attackers to delete arbitrary files. Successful exploitation of this vulnerability requires a site owner to explicitly make an instance of the file manager available to users.
Metrics
Affected Vendors & Products
References
History
Thu, 14 Aug 2025 06:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wordpress
Wordpress wordpress |
|
Vendors & Products |
Wordpress
Wordpress wordpress |
Wed, 13 Aug 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 13 Aug 2025 04:00:00 +0000

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-08-13T03:42:04.514Z
Updated: 2025-08-13T14:01:52.795Z
Reserved: 2025-01-28T21:23:43.968Z
Link: CVE-2025-0818

Updated: 2025-08-13T14:01:49.584Z

Status : Awaiting Analysis
Published: 2025-08-13T04:16:08.373
Modified: 2025-08-13T17:33:46.673
Link: CVE-2025-0818

No data.