← Back to CVE List

CVE-2020-24312

Published: 2020-08-26T13:15Z
Last Modified: 2025-03-24T14:32Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This results in the ability for unauthenticated users to browse and download any site backups, which sometimes include full database backups, that the plugin has taken. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt