← All CVEs NewScan detects
critical

CVE-2020-25213

WP File Manager unauthenticated arbitrary file upload -> RCE

Severity
critical
Affected product
wp-file-manager
Affected versions
wp-file-manager ≥ 6.0, < 6.9
Fixed in
wp-file-manager 6.9
Added to NewScan
2026-07-07
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints wp-file-manager from its response and reports this CVE when the detected version falls inside the affected range below.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →