Exploiting Arbitrary Code in WP File Manager | CVE-2020-25213
The File Manager plugin (wp-file-manager) before version 6.9 for WordPress has a vulnerability that allows remote attackers to upload and execute arbitrary PHP code. The vulnerability arises from the plugin renaming an unsafe example elFinder connector file to have the .php extension, enabling attackers to use elFinder commands to