CVE-2020-25213Patch(filemanagerpro / file_manager)

LOWCVSS 9.8 · CRITICALCISA KEV

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch filemanagerpro file_manager systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php extension. This, for example, allows attackers to run the elFinder upload (or mkfile and put) command to write PHP code into the wp-content/plugins/wp-file-manager/lib/files/ directory. This was exploited in the wild in August and September 2020.

0.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-03. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • file_manager

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Exploit: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-02-16); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
file_manager

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-16: 1Mentions · 2026-07-12: 1Mentions · 2026-08-26: 1Patch / Workaround · 2026-02-16: 1Technical Details · 2026-02-16: 1Technical Details · 2026-08-26: 102-1607-1208-26
Signal classification3 categories
Patch
133.3%
General
133.3%
Exploit
133.3%
Classification over time
DateTotalLabels
2026-02-161
Patch1
2026-07-121
General1
2026-08-261
Exploit1
Full discourse3 posts
  • Abdulmalik_cybersecurity@malik_cybersec
    Exploit

    Day 24/100 Exploited CVE-2020-25213 (WP File Manager 6.0) unauth file upload → PHP webshell → full RCE. Pulled wp-config.php and DB creds. Zero login required. @commando_skiipz @ce3nerd @KoredeSec @DefendWithFelix @ife0x01 https://t.co/Ely30uLnNB

    Post summary

    The tweet reports a successful exploitation of CVE‑2020‑25213 in WP File Manager 6.0 via unauthenticated file upload that achieved full RCE, but no patch or PoC code is provided.

    211174276.7K
    882 followersView on X
  • Rıdvan Yağlı@ridvanyagli
    General

    Saldırganların WordPress, Joomla gibi sistemlere saldırırken kullandığı CVE'ler : – CVE-2026-3844 (WordPress Breeze) – CVE-2026-48907 (Joomla JCE) Diğerleri: CVE-2026-1969, CVE-2026-3300, CVE-2026-0740, CVE-2026-6433, CVE-2025-7443, CVE-2025-7852, CVE-2025-12057, CVE-2020-36847 ve CVE-2020-25213

    Post summary

    The post merely lists CVE identifiers associated with WordPress and Joomla attacks, without providing any PoC, exploit, patch, or technical details.

    1301142.4K
    2.2K followersView on X
  • BlackBoxBrief@BlackBoxBrief
    Patch

    CVE-2020-25213 is a 6-year-old unauthenticated RCE in WordPress File Manager with 700K active installs. Still on CISA KEV because nobody can be bothered to click update. If your vuln management program cannot handle a plugin patch in 6 years, dissolve the team.

    Post summary

    A 6‑year‑old unauthenticated RCE in WordPress File Manager remains on the CISA KEV list, highlighting the need to apply the available plugin update.

    0000059
    37 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfilemanagerprofile_manager-wordpress-

Explore more