CVE · High

CVE-2024-11010 — FileOrganizer – WordPress File Manager [fileorganizer] < 1.1.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-11010 FileOrganizer – WordPress File Manager [fileorganizer] < 1.1.5 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 7.2 < 1.1.5 1.1.5 2024-12-06

CVE-2024-11010

The FileOrganizer – Manage WordPress and Website Files plugin through version 1.1.4 contains a local JavaScript file inclusion vulnerability in the 'default_lang' parameter that permits authenticated administrators to load and run arbitrary JavaScript files from the server. Attackers with administrator privileges could exploit this flaw to execute unauthorized JavaScript code, potentially circumventing security restrictions, accessing confidential information, or executing code when seemingly harmless files such as images have been uploaded. This issue was resolved in version 1.1.5.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.