AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2020-24312

HIGH · CVSS 7.5 EPSS 15.91%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-08-26 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2020-24312
Severity
HIGH
CVSS
7.5
EPSS
15.91%

Original NVD Description

mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This results in the ability for unauthenticated users to browse and download any site backups, which sometimes include full database backups, that the plugin has taken.