WP File Manager 6.8 and earlier lets unauthenticated attackers upload and run PHP files. It has been exploited in the wild; update to 6.9 or later now.
Affected component: File Manager (plugin)
Fixed in: 6.9
Known exploited: this CVE is listed in the CISA Known Exploited Vulnerabilities catalog.
PowerSEC coverage: PowerSEC detects the affected versions on every plan, and has since October 2, 2026. No PowerSEC firewall rule blocks this attack. Update to 6.9 or later to remove the vulnerability.
Full advisory, including detection steps and remediation: https://powersec.io/vulnerability/cve-2020-25213