PT-2026-99245 · Unknown+1 · File Manager+2
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
File Manager WordPress plugin versions prior to 8.0.5
FileOrganizer WordPress plugin versions prior to 1.2.1
File Manager Pro WordPress plugin versions prior to 2.1.3
Description
These plugins fail to correctly validate the origin of window messages received by the file browser loaded on their admin screens. The system accepts any origin that is a leading string prefix of the site's own address. This flaw allows an unauthenticated attacker to execute arbitrary JavaScript within the session of a logged-in administrator who visits a page controlled by the attacker. The issue originates from the bundled
file-manager library in versions prior to 2.1.70.Recommendations
Update File Manager WordPress plugin to version 8.0.5 or later.
Update FileOrganizer WordPress plugin to version 1.2.1 or later.
Update File Manager Pro WordPress plugin to version 2.1.3 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
File Manager
File Manager Pro
Fileorganizer