CVE-2020-25213
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- September 09, 2020
- Published Date
- September 09, 2020
- Last Updated
- October 21, 2025
- Vendor
- WordPress
- Product
- File Manager plugin
- Description
- The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php extension. This, for example, allows attackers to run the elFinder upload (or mkfile and put) command to write PHP code into the wp-content/plugins/wp-file-manager/lib/files/ directory. This was exploited in the wild in August and September 2020.
- Tags
- Exploitation
- active
- Automatable
- Yes
- Technical Impact
- total
- Exploited in the Wild
- Yes (2021-11-03 00:00:00 UTC) Source
CVSS Scores
CVSS v3.1
Vector: CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:C/UI:N
SSVC Information
Exploit Status
References
Known Exploited Vulnerability Information
| Source | Added Date |
|---|---|
| CISA | 2021-11-03 00:00:00 UTC |
| CISA | 2021-11-03 00:00:00 UTC |
Scanner Integrations
| Scanner | URL | Date Detected |
|---|---|---|
| Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/wp_file_manager_rce.rb | 2025-04-28 15:02:26 UTC |
| Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-25213.yaml | 2025-04-25 00:00:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
wp_file_manager_rce
Type: metasploit • Created: Unknown
E1tex/Python-CVE-2020-25213
Type: github • Created: 2023-08-02 09:06:13 UTC • Stars: 3
BLY-Coder/Python-exploit-CVE-2020-25213
Type: github • Created: 2023-01-22 16:54:25 UTC • Stars: 6
b1ackros337/CVE-2020-25213
Type: github • Created: 2022-05-24 16:35:23 UTC • Stars: 0
piruprohacking/CVE-2020-25213
Type: github • Created: 2021-04-03 13:52:21 UTC • Stars: 0
mansoorr123/wp-file-manager-CVE-2020-25213
Type: github • Created: 2020-10-10 17:50:01 UTC • Stars: 57
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Added to KEVIntel
-
Added to KEVIntel
-
Detected by Nuclei
-
Detected by Metasploit