WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in File Manager

file manager provides you ability to edit, delete, upload, download, copy and paste files and folders.

11Reported vulnerabilities
9.9Highest CVSS score
8.0.4Latest version
1,000,000+Active installs

What to do now

Update File Manager to 8.0.4 or later. 11 of these have a fixed version available. Updating resolves them.

Plugin last updated: April 21, 2026 / Tested up to WordPress: 6.9.7 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2020-25213
Exploited
Critical 9.8 97.3% 6.8 and earlier 6.9 September 9, 2020
CVE-2020-24312 High 7.5 15.9% 6.4 and earlier 6.5 August 13, 2020
CVE-2018-16966 High 8.8 0.9% 3.0 to 3.0 (inclusive) 3.1 April 15, 2019
CVE-2024-1538 High 8.8 10.7% 0 to 7.2.4 (inclusive)
0 to 7.2.4 (inclusive)
7.2.5 March 21, 2024
CVE-2023-6825 Critical 9.9 6.0% 7.2.1 and earlier 7.2.2 March 4, 2024
CVE-2018-16967 Medium 6.1 1.4% 3.0 to 3.0 (inclusive) 3.1 April 15, 2019
CVE-2024-0761 High 7.5 1.0% 7.2.1 and earlier 7.2.2 February 5, 2024
CVE-2026-6382 High 7.2 1.4% Before 8.0.4 8.0.4 June 15, 2026
CVE-2024-2654 Medium 6.8 0.9% 0 to 7.2.5 (inclusive) 7.2.6 April 9, 2024
WF-077b3483-ab1c-401d-aa67-c4da5fca90b4 Medium 6.3 4.8 and earlier 4.9 August 7, 2019
CVE-2024-37254 Medium 4.3 0.3% 7.2.7 and earlier 7.2.8 June 27, 2024

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.