Summary
This advisory addresses CVE-2020-25213, a remote code execution vulnerability. It affects the File Manager (wp-file-manager) plugin for WordPress. The vulnerability is patched in version 6.9 and later. This vulnerability was exploited in the wild in August and September 2020.
Affected and patched versions
Affected Versions | Patched Versions |
|---|---|
6.8 and earlier | 6.9 or later |
Is my site vulnerable?
To determine if your WordPress site is vulnerable to CVE-2020-25213, you need to check the version of the File Manager (wp-file-manager) plugin installed on your site. If your site uses the File Manager plugin and its version is between 6.0 and 6.9, it is affected by this vulnerability. Specifically, version 6.8 was confirmed to be vulnerable.
You can check the plugin version through your WordPress administration dashboard. Log in to your WordPress site as an administrator. Navigate to the "Plugins" section in the left-hand menu, then select "Installed Plugins." Locate "File Manager" in the list of installed plugins. The version number will be displayed next to the plugin's name.
Alternatively, you can check the plugin's version by accessing your site's file system via SFTP or your hosting control panel's file manager. Navigate to the wp-content/plugins/wp-file-manager/ directory. Inside this directory, you will typically find a readme.txt file or the main plugin file (e.g., wp-file-manager.php). Open this file and look for a "Version" header, which will indicate the installed version number. Compare this version number against the affected versions listed in this advisory. If your installed version is 6.9 or higher, your site is not vulnerable to this specific issue. If it is 6.8 or earlier, your site is vulnerable.
What an attacker actually does
An attacker exploits this vulnerability by targeting a specific file within the File Manager plugin. The File Manager plugin before version 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code. This occurs because the plugin renames an unsafe example elFinder connector file to have the .php extension. This renamed file then becomes accessible and executable.
This renamed file, which should have been protected, allows anyone to upload files to the WordPress site without needing to log in or authenticate. The vulnerability stems from a class that reads POST/GET variables and permits the execution of internal features, including file uploads, without requiring authentication. Since PHP files are allowed to be uploaded, this results in an unauthenticated arbitrary file upload capability, which directly leads to remote code execution.
For example, an attacker can run the elFinder upload, mkfile, or put commands to write malicious PHP code into the wp-content/plugins/wp-file-manager/lib/files/ directory. Once a malicious PHP file, often referred to as a "webshell," is successfully uploaded to this directory, the attacker can then execute it. This grants them control over the affected WordPress website and potentially the server it runs on. This control allows attackers to perform various malicious actions, such as installing additional malware, stealing sensitive data, defacing the website, or using the compromised server for further attacks.
How to detect a compromise
Detecting a compromise related to CVE-2020-25213 involves looking for unauthorized or suspicious files within the File Manager plugin's directories, particularly where arbitrary files could have been uploaded. The primary indicator of compromise is the presence of unexpected PHP files in specific locations.
Attackers are known to write PHP code into the wp-content/plugins/wp-file-manager/lib/files/ directory. Therefore, you should audit this directory for any files that do not belong to the legitimate plugin installation. Look for files with unusual names, recent modification dates that do not align with plugin updates, or files that appear to be webshells or other malicious scripts.
Steps to detect a compromise:
Inspect the `wp-content/plugins/wp-file-manager/lib/files/` directory: Access your WordPress site's file system using SFTP, SSH, or your hosting provider's file manager. Navigate to the
wp-content/plugins/wp-file-manager/lib/files/directory.Look for suspicious PHP files: Examine the contents of this directory for any
.phpfiles that you do not recognize as part of the standard File Manager plugin. Legitimate installations of the plugin should not contain arbitrary PHP files in this specific subdirectory.Check file modification dates: Pay close attention to the modification dates of any PHP files found in this directory. Files with recent modification dates, especially those coinciding with the period when the vulnerability was exploited in the wild (August and September 2020) or any other suspicious activity on your site, are strong indicators of compromise.
Use command-line tools (if available): If you have SSH access to your server, you can use command-line tools to list files and their properties.
To list all PHP files in the target directory and its subdirectories, along with their modification times:
find wp-content/plugins/wp-file-manager/lib/files/ -name "*.php" -type f -print0 | xargs -0 ls -ltThis command will show you a list of PHP files sorted by modification time, with the most recently modified files at the top. Review these files for anything unexpected.
You can also search for specific strings commonly found in webshells, though this requires caution as legitimate files might contain similar strings. However, for files in the lib/files/ directory, any PHP file is suspicious.
If you find any unauthorized or suspicious PHP files in the wp-content/plugins/wp-file-manager/lib/files/ directory, it indicates a likely compromise.
How to fix
Addressing CVE-2020-25213 involves updating the File Manager plugin and performing cleanup if a compromise is detected.
Update the File Manager plugin: The most direct and effective fix is to immediately update the File Manager plugin to version 6.9 or later. This version contains the patch that resolves the arbitrary file upload vulnerability. You can update the plugin through your WordPress administration dashboard by navigating to "Plugins" > "Installed Plugins" and clicking "Update Now" next to the File Manager plugin, or by manually downloading the latest version from the WordPress plugin repository and installing it.
Deactivate and remove the vulnerable plugin (if immediate patching is not possible): If you cannot immediately update the plugin, or if you do not actively use the File Manager plugin, deactivating and removing the vulnerable plugin is recommended until patching can occur. This removes the vulnerable code from your site, eliminating the attack vector.
Audit and clean the affected directory: After updating or removing the plugin, it is advised to audit the
wp-content/plugins/wp-file-manager/lib/files/directory for any unauthorized or suspicious PHP files. If a compromise occurred, malicious files may still reside on your server even after the plugin is updated. Carefully review and remove any files in this directory that are not part of the legitimate plugin installation. If you are unsure about a file, it is safer to back it up and then remove it, or consult with a security professional.
Timeline
Date | Event |
|---|---|
2020-08-01 | Exploited in the wild |
2020-08-26 | Public disclosure |
2020-09-09 | CVE Published |
Sources
https://nvd.nist.gov/vuln/detail/CVE-2020-25213
https://www.wordfence.com/threat-intel/vulnerabilities/id/dab7e451-f2ea-4f41-8e38-a2a983ccb18b
https://wpscan.com/vulnerability/e528ae38-72f0-49ff-9878-922eff59ace9/
https://www.cve.org/CVERecord?id=CVE-2020-25213