CVE-2025-9345 Overview
CVE-2025-9345 is a path traversal vulnerability [CWE-22] affecting the File Manager, Code Editor, and Backup by Managefy plugin for WordPress. The flaw exists in the ajax_downloadfile() function across all plugin versions up to and including 1.4.8. Authenticated attackers with Subscriber-level access or higher can traverse directory paths and read files outside the plugin's intended working directory. The vulnerability enables unauthorized disclosure of sensitive files on the underlying WordPress server, including configuration files that may contain database credentials and authentication secrets.
Critical Impact
Authenticated Subscriber-level users can read arbitrary files on the WordPress host, exposing credentials stored in wp-config.php and other sensitive server files.
Affected Products
- File Manager, Code Editor, and Backup by Managefy plugin for WordPress
- All plugin versions up to and including 1.4.8
- WordPress sites with Subscriber-level or higher registration enabled
Discovery Timeline
- 2025-08-28 - CVE-2025-9345 published to the National Vulnerability Database
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-9345
Vulnerability Analysis
The vulnerability resides in the ajax_downloadfile() handler exposed by the plugin's AJAX interface. The function accepts a user-supplied file path parameter and passes it to file-read logic without sanitizing directory traversal sequences such as ../. An authenticated attacker submits a crafted request that walks up the directory tree and returns the contents of files outside the plugin's intended scope.
The impact is limited to confidentiality. The CWE-22 classification confirms improper limitation of a pathname to a restricted directory. Exposure of files such as wp-config.php yields database credentials, authentication keys, and salts that support downstream attacks including database compromise and session forgery.
The Exploit Prediction Scoring System places this issue in the lower probability range for near-term mass exploitation, but WordPress plugin vulnerabilities are routinely folded into automated attack toolkits once public proof-of-concept code appears.
Root Cause
The ajax_downloadfile() function fails to validate or canonicalize the requested file path before opening and streaming the file. Missing checks for ../ sequences, absolute paths, and path canonicalization allow the attacker-controlled input to reference locations outside the plugin's designated directory.
Attack Vector
Exploitation requires an authenticated WordPress account with Subscriber privileges or higher. The attacker issues an authenticated HTTP POST request to the plugin's AJAX endpoint, supplying a file path parameter containing traversal sequences that resolve to sensitive server files. The response contains the raw contents of the targeted file. No user interaction is required beyond the attacker's authenticated session.
No verified public proof-of-concept code was available at the time of writing. See the Wordfence Vulnerability Report and the WordPress Plugin Changeset for the technical fix diff.
Detection Methods for CVE-2025-9345
Indicators of Compromise
- POST requests to admin-ajax.php with the action parameter targeting the plugin's downloadfile handler and payloads containing ../ sequences.
- Unexpected WordPress access log entries where Subscriber-level accounts issue AJAX file-download requests.
- Web server responses returning contents of wp-config.php, /etc/passwd, or other files outside the plugin's install directory.
Detection Strategies
- Inspect WordPress access logs and web application firewall telemetry for AJAX requests referencing traversal patterns such as ..%2f, ..\, or absolute filesystem paths.
- Correlate low-privilege session activity with file-download AJAX actions that would not normally originate from Subscriber accounts.
- Alert on repeated 200-status responses to the downloadfile action from a single authenticated session in a short time window.
Monitoring Recommendations
- Enable verbose logging on the WordPress instance and forward logs to a centralized analytics platform for retention and search.
- Monitor filesystem access on wp-config.php and other sensitive files, and alert on reads originating from the web server user outside deployment windows.
- Track newly registered Subscriber accounts followed by immediate AJAX activity against plugin endpoints.
How to Mitigate CVE-2025-9345
Immediate Actions Required
- Update the File Manager, Code Editor, and Backup by Managefy plugin to a version later than 1.4.8 as soon as the vendor publishes a fixed release.
- Audit WordPress user accounts and remove or disable unnecessary Subscriber-level accounts, especially those created through open registration.
- Rotate WordPress secrets in wp-config.php, database credentials, and any API keys exposed on the server if compromise is suspected.
Patch Information
Review the WordPress Plugin Changeset for the upstream code fix and confirm the deployed plugin version reflects the patched release. The Wordfence Vulnerability Report tracks patched version metadata.
Workarounds
- Deactivate and remove the plugin until a patched version is installed if the plugin's functionality is not business-critical.
- Disable open user registration or restrict registration to trusted email domains to reduce the attacker's ability to obtain Subscriber accounts.
- Deploy a web application firewall rule that blocks requests to admin-ajax.php where the payload contains ../, ..\, or URL-encoded traversal sequences targeting the plugin's AJAX actions.
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
