
Day 24/100 Exploited CVE-2020-25213 (WP File Manager 6.0) unauth file upload → PHP webshell → full RCE. Pulled wp-config.php and DB creds. Zero login required. @commando_skiipz @ce3nerd @KoredeSec @DefendWithFelix @ife0x01 https://t.co/Ely30uLnNB
Post summary
The tweet reports a successful exploitation of CVE‑2020‑25213 in WP File Manager 6.0 via unauthenticated file upload that achieved full RCE, but no patch or PoC code is provided.


