LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-25213: WordPress File Manager Plugin Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-25213 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site.

CVE-2020-25213 is a remote code execution vulnerability in the WordPress File Manager plugin. It allows unauthenticated users to execute PHP code and upload malicious files on a target site. For IT and security teams running WordPress, this matters because a widely used file-management plugin can become an unauthenticated entry point that lets an attacker place and run code directly on the web server, potentially leading to full site compromise.

Public detail is limited to the CISA description and the associated weakness class. Confirm exact affected releases, fixed versions, and any configuration prerequisites against the vendor advisory before acting.

How it works

The vulnerability is classified as CWE-434, unrestricted upload of a file with a dangerous type. In this class of flaw, the application accepts file uploads without adequately restricting the types of files that may be stored or the locations in which they may be written, and without preventing subsequent execution of those files.

According to the CISA summary, an unauthenticated attacker can abuse the File Manager plugin to upload malicious files and execute PHP code on the target WordPress site. The attacker does not need valid credentials. Once a malicious PHP file is present and reachable, the attacker can invoke it to run arbitrary code in the context of the web server process. Specific exploit mechanics, request formats, or payload details are not provided here; treat any public proof-of-concept material with caution and validate findings only against the vendor advisory and your own controlled testing.

Am I affected? How to find it in your systems

The affected component is the WordPress File Manager plugin. It typically appears on WordPress sites where administrators have installed a plugin that provides web-based file browsing, upload, edit, or management capabilities inside the wp-admin or via front-end shortcodes.

How to remediate

Patch first. Apply the updates per the vendor instructions, as required by CISA. Install the security release that addresses CVE-2020-25213 on every WordPress instance that carries the plugin, then verify the new version is active.

If you can't patch immediately

If an immediate update is not possible, reduce risk with compensating controls until the vendor patch can be applied.

If your data may have been exposed

Actively exploited remote-code-execution vulnerabilities frequently lead to site takeover, data theft, or further lateral movement. Known ransomware use is not documented for this CVE, but that does not rule out other malicious activity. If you suspect exploitation, isolate the host, preserve logs and disk images, and follow your incident-response process. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether associated credentials have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedWordPress · File Manager Plugin
WeaknessCWE-434
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities