RULE(RULE ID:331024)

Rule General Information
Release Date: 2020-09-04
Rule Name: Wordpress File Manager File Upload Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: WordPress is a blogging platform developed by the Wordpress Foundation using the PHP language. The platform supports hosting personal blog sites on PHP and MySQL servers. File Manager, a WordPress plugin. This plugin has a file upload vulnerability, which allows attackers to execute arbitrary code under the plugins/wp-file-manager/lib/files/ link.
Impact: In the affected version, attackers can use this vulnerability to upload files and then execute arbitrary code.
Affected OS: Windows, Linux, Others
Reference: https://arstechnica.com/information-technology/2020/09/hackers-are-exploiting-a-critical-flaw-affecting-350000-wordpress-sites/
https://www.solidot.org/story?sid=65420
Solutions
Check the Wordpress File Manager plug-in to make sure the version number is 6.9 and above.