
wp-file-manager 6.7 (2020年8月) WordPressプラグイン 0day - リモートコード実行
elFinderの脆弱性はよく知られた脆弱性です。私のスクリプトはパスを "/wp-content/plugins/wp-file-manager/" に変更するだけです。私にスクリプトの修正やその他の修正を要求するのはやめろ。RTFM...
参照:
https://www.exploit-db.com/exploits/46481
https://www.exploit-db.com/exploits/46539
https://twitter.com/w4fz5uck5/status/1303396627198152707
https://wpvulndb.com/vulnerabilities/10389