HIGH
WordPress File Manager Plugin <= 5.2.7 is vulnerable to PHP Object Injection
Published Dec 20, 2023
7.2
HIGHCVSS 3.1
EPSS 0.52%
Description
Deserialization of Untrusted Data vulnerability in File Manager by Bit Form Team File Manager – 100% Free & Open Source File Manager Plugin for WordPress | Bit File Manager.This issue affects File Manager – 100% Free & Open Source File Manager Plugin for WordPress | Bit File Manager: from n/a through 5.2.7.
Affected products
-
Affected
- ≤ 5.2.7
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| File Manager by Bit Form Team | n/a | unaffected | Affected
|
- < 6.0.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Update to 6.0.0 or a higher version.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-50359 Advisory
- https://patchstack.com/database/vulnerability/file-manager/wordpress-bit-file-manager-100-free-file-manager-for-wordpress-plugin-5-2-7-php-object-injection?_s_id=cve vdb-entryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-50359 | Advisory | |
| https://patchstack.com/database/vulnerability/file-manager/wordpress-bit-file-manager-100-free-file-manager-for-wordpress-plugin-5-2-7-php-object-injection?_s_id=cve | vdb-entryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Patchstack
Published Dec 20, 2023
Updated Apr 28, 2026
Reserved Dec 20, 2022
Link CVE-2022-47599
CISA Vulnrichment
Updated May 6, 2025
Red Hat
No data
GitHub
No data