Skip to main content

Vendor/product archive

ninjateam / filester CVEs

Beta · best-effort

7 CVEs tagged to ninjateam / filester0 Critical, 5 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2024-12331

Published Dec 19, 2024

The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_install_plugin' function in…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9669

Published Nov 28, 2024

The File Manager Pro – Filester plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 1.8.5 via the 'fm_locale' parameter. Th…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8066

Published Nov 28, 2024

The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing validation in the 'fsConnector' function in all versions up to, and inc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-7031

Published Aug 3, 2024

The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'njt_fs_saveSettingRestrictions' f…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-4862

Published Oct 16, 2023

The File Manager Pro WordPress plugin before 1.8.1 does not adequately validate and escape some inputs, leading to XSS by high-privilege users.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4861

Published Oct 16, 2023

The File Manager Pro WordPress plugin before 1.8.1 allows admin users to upload arbitrary files, even in environments where such a user should not be able to gain full control of…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-4827

Published Oct 16, 2023

The File Manager Pro WordPress plugin before 1.8 does not properly check the CSRF nonce in the `fs_connector` AJAX action. This allows attackers to make highly privileged users pe…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1