Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4187 articles · 222180 vulns · 36/41 feeds (7d)
← Back to list
9.1
CVE-2026-6382EXPLOITEDPATCHED
wordpress · fileorganizer

Multiple elFinder Plugins - Authenticated OS Command Injection

Description

The FileOrganizer WordPress plugin before 1.1.9, Advanced File Manager WordPress plugin before 5.4.12, File Manager Pro WordPress plugin before 2.1.1, File Manager WordPress plugin before 8.0.4 do not properly escape a parameter before passing it to a shell command when processing image operations, allowing authenticated users to perform OS Command Injection. This requires the server to have the ImageMagick convert CLI available without either the PHP imagick or GD extensions.

Affected Products

VendorProductVersions
wordpressfileorganizer0, 0, 0, 0

References

  • https://wpscan.com/vulnerability/a27f70b7-a4cc-42fa-88c1-19adfe1593a8/(exploit, vdb-entry, technical-description)

Related News (1 articles)

Tier C
VulDB80d ago
CVE-2026-6382 | FileOrganizer Plugin on WordPress os command injection
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.1 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
1.1.95.4.122.1.18.0.4
PublishedJul 6, 2026
Last enriched80d agov2
Trending Score0
Source articles1
Independent1
Info Completeness7/14
Missing: cvss, epss, cwe, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-87902EXPKEV
CVE-2026-87902: An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.ph
Trending: 135
CRITICALCVE-2026-63030EXPKEV
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
Trending: 4
MEDIUMCVE-2026-60137EXPKEV
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
Trending: 3
HIGHCVE-2026-65640
CVE-2026-65640: WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level
Trending: 1
NONECVE-2026-64638
CVE-2026-64638: WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
Trending: 1

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 6, 2026
Discovered by ZDM
Jul 6, 2026
Updated: description, severity, activelyExploited
Jul 6, 2026
Actively Exploited
Jul 6, 2026
Patch Available
Jul 6, 2026

Version History

v2
Last enriched 80d ago
v2Tier C80d ago

Updated severity to CRITICAL, marked as actively exploited, and corrected exploit availability to false.

descriptionseverityactivelyExploited
via VulDB
v180d ago

Initial creation