CVE-2023-6825PoC(mndpsingh287 / file_manager)

LOWCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and including version 7.2.1 (free version) and 8.3.4 (Pro version) via the target parameter in the mk_file_folder_manager_action_callback_shortcode function. This makes it possible for attackers to read the contents of arbitrary files on the server, which can contain sensitive information and to upload files into directories other than the intended directory for file uploads. The free version requires Administrator access for this vulnerability to be exploitable. The Pro version allows a file manager to be embedded via a shortcode and also allows admins to grant file handling privileges to other user levels, which could lead to this vulnerability being exploited by lower-level users.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-23CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • file_manager

Threat summary

  • Public PoC is present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
file_manager

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-09: 1PoC Mentioned / Linked · 2026-04-09: 1Technical Details · 2026-04-09: 104-09
Signal classification1 categories
PoC
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • pdnuclei-bot@pdnuclei_bot
    PoC

    🚨 CVE-2023-6825 - critical 🚨 WordPress File Manager <= 7.2.1 - Directory Traversal > File Manager and File Manager Pro plugins for WordPress versions up to 7.2.1 and 8.3.... 👾 https://cloud.projectdiscovery.io/library/CVE-2023-6825 @pdnuclei #NucleiTemplates #cve

    Post summary

    This tweet highlights the discovery of CVE-2023-6825, a critical directory traversal flaw in WordPress File Manager plugins, and shares a link to the corresponding PoC, with no mention of patches or active exploitation.

    00010127
    916 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appmndpsingh287file_manager-wordpress-
Appmndpsingh287file_manager-wordpress-

Explore more