CVE-2024-7031 Information

Description

The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ’njt_fs_saveSettingRestrictions’ function in all versions up to and including 1.8.2. This makes it possible for authenticated attackers with a role that has been granted permissions by an Administrator to update the plugin settings for user role restrictions including allowing file types such as .php to be uploaded.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Reference

https://www.wordfence.com/threat-intel/vulnerabilities/id/aef584bd-60a5-4bf2-b8d3-58e3b45e785e?source=cve https://plugins.trac.wordpress.org/browser/filester/trunk/includes/File_manager/FileManager.php#L566 https://plugins.trac.wordpress.org/changeset/3129722/

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

7.5

Share on: