Advisory

CVE-2020-25213 in File Manager

Known exploitedCVSS 10.0 (CVE record)Published Sep 30, 2026Last verified Oct 7, 2026

WP File Manager 6.8 and earlier lets unauthenticated attackers upload and run PHP files. It has been exploited in the wild; update to 6.9 or later now.

Exploited in the wild
Yes (CISA KEV)
Installs not updated
0%
Affected and fixed versions
ComponentAffectedFixed in
File Manager (plugin)6.8 and earlier6.9
Run a free scan of your site

The free scan checks what is visible from outside your site. It does not log in, and it cannot confirm on its own whether this specific issue is present.

Summary

This advisory addresses CVE-2020-25213, a remote code execution vulnerability. It affects the File Manager (wp-file-manager) plugin for WordPress. The vulnerability is patched in version 6.9 and later. This vulnerability was exploited in the wild in August and September 2020.

Affected and patched versions

Affected Versions

Patched Versions

6.8 and earlier

6.9 or later

Is my site vulnerable?

To determine if your WordPress site is vulnerable to CVE-2020-25213, you need to check the version of the File Manager (wp-file-manager) plugin installed on your site. If your site uses the File Manager plugin and its version is between 6.0 and 6.9, it is affected by this vulnerability. Specifically, version 6.8 was confirmed to be vulnerable.

You can check the plugin version through your WordPress administration dashboard. Log in to your WordPress site as an administrator. Navigate to the "Plugins" section in the left-hand menu, then select "Installed Plugins." Locate "File Manager" in the list of installed plugins. The version number will be displayed next to the plugin's name.

Alternatively, you can check the plugin's version by accessing your site's file system via SFTP or your hosting control panel's file manager. Navigate to the wp-content/plugins/wp-file-manager/ directory. Inside this directory, you will typically find a readme.txt file or the main plugin file (e.g., wp-file-manager.php). Open this file and look for a "Version" header, which will indicate the installed version number. Compare this version number against the affected versions listed in this advisory. If your installed version is 6.9 or higher, your site is not vulnerable to this specific issue. If it is 6.8 or earlier, your site is vulnerable.

What an attacker actually does

An attacker exploits this vulnerability by targeting a specific file within the File Manager plugin. The File Manager plugin before version 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code. This occurs because the plugin renames an unsafe example elFinder connector file to have the .php extension. This renamed file then becomes accessible and executable.

This renamed file, which should have been protected, allows anyone to upload files to the WordPress site without needing to log in or authenticate. The vulnerability stems from a class that reads POST/GET variables and permits the execution of internal features, including file uploads, without requiring authentication. Since PHP files are allowed to be uploaded, this results in an unauthenticated arbitrary file upload capability, which directly leads to remote code execution.

For example, an attacker can run the elFinder upload, mkfile, or put commands to write malicious PHP code into the wp-content/plugins/wp-file-manager/lib/files/ directory. Once a malicious PHP file, often referred to as a "webshell," is successfully uploaded to this directory, the attacker can then execute it. This grants them control over the affected WordPress website and potentially the server it runs on. This control allows attackers to perform various malicious actions, such as installing additional malware, stealing sensitive data, defacing the website, or using the compromised server for further attacks.

How to detect a compromise

Detecting a compromise related to CVE-2020-25213 involves looking for unauthorized or suspicious files within the File Manager plugin's directories, particularly where arbitrary files could have been uploaded. The primary indicator of compromise is the presence of unexpected PHP files in specific locations.

Attackers are known to write PHP code into the wp-content/plugins/wp-file-manager/lib/files/ directory. Therefore, you should audit this directory for any files that do not belong to the legitimate plugin installation. Look for files with unusual names, recent modification dates that do not align with plugin updates, or files that appear to be webshells or other malicious scripts.

Steps to detect a compromise:

  1. Inspect the `wp-content/plugins/wp-file-manager/lib/files/` directory: Access your WordPress site's file system using SFTP, SSH, or your hosting provider's file manager. Navigate to the wp-content/plugins/wp-file-manager/lib/files/ directory.

  2. Look for suspicious PHP files: Examine the contents of this directory for any .php files that you do not recognize as part of the standard File Manager plugin. Legitimate installations of the plugin should not contain arbitrary PHP files in this specific subdirectory.

  3. Check file modification dates: Pay close attention to the modification dates of any PHP files found in this directory. Files with recent modification dates, especially those coinciding with the period when the vulnerability was exploited in the wild (August and September 2020) or any other suspicious activity on your site, are strong indicators of compromise.

  4. Use command-line tools (if available): If you have SSH access to your server, you can use command-line tools to list files and their properties.

To list all PHP files in the target directory and its subdirectories, along with their modification times:

find wp-content/plugins/wp-file-manager/lib/files/ -name "*.php" -type f -print0 | xargs -0 ls -lt

This command will show you a list of PHP files sorted by modification time, with the most recently modified files at the top. Review these files for anything unexpected.

You can also search for specific strings commonly found in webshells, though this requires caution as legitimate files might contain similar strings. However, for files in the lib/files/ directory, any PHP file is suspicious.

If you find any unauthorized or suspicious PHP files in the wp-content/plugins/wp-file-manager/lib/files/ directory, it indicates a likely compromise.

How to fix

Addressing CVE-2020-25213 involves updating the File Manager plugin and performing cleanup if a compromise is detected.

  1. Update the File Manager plugin: The most direct and effective fix is to immediately update the File Manager plugin to version 6.9 or later. This version contains the patch that resolves the arbitrary file upload vulnerability. You can update the plugin through your WordPress administration dashboard by navigating to "Plugins" > "Installed Plugins" and clicking "Update Now" next to the File Manager plugin, or by manually downloading the latest version from the WordPress plugin repository and installing it.

  2. Deactivate and remove the vulnerable plugin (if immediate patching is not possible): If you cannot immediately update the plugin, or if you do not actively use the File Manager plugin, deactivating and removing the vulnerable plugin is recommended until patching can occur. This removes the vulnerable code from your site, eliminating the attack vector.

  3. Audit and clean the affected directory: After updating or removing the plugin, it is advised to audit the wp-content/plugins/wp-file-manager/lib/files/ directory for any unauthorized or suspicious PHP files. If a compromise occurred, malicious files may still reside on your server even after the plugin is updated. Carefully review and remove any files in this directory that are not part of the legitimate plugin installation. If you are unsure about a file, it is safer to back it up and then remove it, or consult with a security professional.

Timeline

Date

Event

2020-08-01

Exploited in the wild

2020-08-26

Public disclosure

2020-09-09

CVE Published

Sources

  • https://nvd.nist.gov/vuln/detail/CVE-2020-25213

  • https://www.wordfence.com/threat-intel/vulnerabilities/id/dab7e451-f2ea-4f41-8e38-a2a983ccb18b

  • https://wpscan.com/vulnerability/e528ae38-72f0-49ff-9878-922eff59ace9/

  • https://www.cve.org/CVERecord?id=CVE-2020-25213

PowerSEC coverage
PowerSEC detects the affected versions on every plan, and has since October 2, 2026. No PowerSEC firewall rule blocks this attack. Update to 6.9 or later to remove the vulnerability.
This record contains material that is subject to copyright Copyright 2012-2026 Defiant Inc. Copyright 1999-2026 The MITRE Corporation
Hacked? Talk to us
CVE-2020-25213 in File Manager | PowerSEC