Etavrian
keyboard_arrow_right Created with Sketch.
News
keyboard_arrow_right Created with Sketch.

File deletion flaw affects 3 WordPress file managers with up to 1.3 million installs - are you exposed?

Reviewed:
Andrii Daniv
1
min read
Aug 13, 2025
Minimalist illustration of worried user noticing WordPress file manager with public toggle risking file deletion

Wordfence disclosed a directory traversal flaw in the elFinder component used by three WordPress file manager plugins. The bug enables arbitrary file deletion and may affect up to 1.3 million sites, according to the Wordfence advisory. Unauthenticated exploitation is possible only if a site exposes the file manager interface publicly.

Vulnerability In 3 WordPress File Plugins Affects 1.3 Million Sites
Wordfence reports a directory traversal flaw in elFinder-based file manager plugins impacting up to 1.3 million sites.

Key details

  • The issue is a directory traversal to arbitrary file deletion vulnerability in elFinder versions 2.1.64 and earlier embedded by affected plugins.
  • Attackers can manipulate file paths to escape allowed directories and delete files outside permitted folders.
  • Unauthenticated exploitation is possible only when a site publicly exposes the file manager endpoint.
  • Affected plugins named by Wordfence: File Manager, Advanced File Manager, and Filester - File Manager Pro.
  • These plugins collectively account for up to 1.3 million installations, per the Wordfence advisory.

Background

ElFinder is a third-party file manager library integrated by several WordPress file management plugins. Versions 2.1.64 and earlier contain a directory traversal flaw that allows path manipulation using traversal sequences to reach files outside the intended directory. Wordfence, which operates a public vulnerability database, identified the vulnerable elFinder versions within the three plugins and outlined exploitation conditions. For project details, see the elFinder project repository.

What site owners can do

Sources

Quickly summarize and get insighs with: 
Author
Etavrian AI
Etavrian AI is developed by Andrii Daniv to produce and optimize content for etavrian.com website.
Reviewed
Andrew Daniv, Andrii Daniv
Andrii Daniv
Andrii Daniv is the founder and owner of Etavrian, a performance-driven agency specializing in PPC and SEO services for B2B and e‑commerce businesses.
Quickly summarize and get insighs with: 
Table of contents