A medium-risk security flaw has been patched in WordPress File Manager 8.4.2 and other plugins using outdated versions of the elFinder file management library (2.1.64 and earlier).
The bug, known as a Directory Traversal vulnerability, could let unauthenticated users delete any file on a site’s server. The exploit works if the site owner has given users access to a file manager tool without proper restrictions.
Affected plugins include:
- Advanced File Manager – Ultimate WP File Manager and Document Library Solution (patched in latest release)
- File Manager Pro – Filester (patched in version 1.8.9)
Developers have fixed the flaw by improving input validation to block malicious file path requests.
Security experts advise site owners to update to the latest plugin versions and ensure file managers are not accessible to the public.
Bijay Pokharel
Bijay Pokharel is the Founder and Editor-in-Chief of Abijita.com and a freelance technology writer covering the tech industry since 2017. He specializes in cybersecurity, digital privacy, malware, vulnerabilities, and online safety, with a strong interest in internet protection and women’s online security. A dedicated tech enthusiast and continuous learner, Bijay approaches his professional work with clarity, rational thinking, and a calm, solution-oriented mindset.





