PoC Index

CVE-2020-25213

KEVCRITICAL 10.0EPSS 97.3%

The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php extension. This, for example, allows attackers to run the elFinder upload (or mkfile and put) command to write PHP code into the wp-content/plugins/wp-file-manager/lib/files/ directory. This was exploited in the wild in August and September 2020.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
10.0 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
97.33% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2021-11-03
Nuclei
critical · CWE-434
Published
2020-09-09
Updated
2025-10-21

Proof-of-concept exploits (17)

Nuclei templates (1)

Metasploit modules (1)

ExploitDB entries (2)

Exploit collections (1)

References

Related