File Manager Security & Risk Analysis

wordpress.org/plugins/file-manager

File Manager lets you manage your WordPress files easily right from your dashboard, no need for FTP or cPanel!

10K active installs v6.9 PHP 7.4+ WP 5.0+ Updated Jul 7, 2026
file-managerfilesftpwordpress-file-managerwp-file-manager
94
A · Safe
CVEs total9
Unpatched0
Last CVEJun 2, 2025
Safety Verdict

Is File Manager Safe to Use in 2026?

Generally Safe

Score 94/100

File Manager has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

9 known CVEsLast CVE: Jun 2, 2025Updated 1mo ago
Risk Assessment
Assessment pending
Vulnerabilities
9 published

File Manager Security Vulnerabilities

CVEs by Year

1 CVE in 2017
2017
1 CVE in 2018
2018
1 CVE in 2022
2022
2 CVEs in 2023
2023
3 CVEs in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

High
6
Medium
2
Low
1

9 total CVEs

CVE-2025-1725medium · 6.4Unrestricted Upload of File with Dangerous Type

Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress <= 6.7 - Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File Uploads

Jun 2, 2025 Patched in 6.8 (1d)
CVE-2024-8743medium · 6.8Unrestricted Upload of File with Dangerous Type

Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress <= 6.5.7 - Authenticated (Subscriber+) Limited JavaScript File Upload

Oct 4, 2024 Patched in 6.5.8 (1d)
CVE-2024-7770high · 8.8Unrestricted Upload of File with Dangerous Type

Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress <= 6.5.5 - Authenticated (Subscriber+) Arbitrary File Upload

Sep 9, 2024 Patched in 6.5.6 (1d)
CVE-2024-7627high · 8.1Improper Control of Generation of Code ('Code Injection')

Bit File Manager 6.0 - 6.5.5 - Unauthenticated Remote Code Execution via Race Condition

Sep 4, 2024 Patched in 6.5.6 (1d)
CVE-2023-5907low · 2.2Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

File Manager <= 6.3 - Authenticated (Admin+) Arbitrary OS File Access via Path Traversal

Nov 20, 2023 Patched in 6.3 (64d)
CVE-2022-47599high · 7.2Deserialization of Untrusted Data

Bit File Manager <= 5.2.7 - Authenticated (Admin+) PHP Object Injection

Apr 28, 2023 Patched in 6.0 (270d)
CVE-2022-0403high · 8.8Unrestricted Upload of File with Dangerous Type

Bit File Manager – 100% free file manager for WordPress <= 5.2.2 - Subscriber+ Arbitrary File Creation/Upload/Deletion

Mar 14, 2022 Patched in 5.2.3 (680d)
CVE-2018-7204high · 7.5Insertion of Sensitive Information into Log File

Bit File Manager <= 5.0.0 - Information Disclosure

Mar 2, 2018 Patched in 5.0.2 (2153d)
WF-37052cb9-8479-4004-9161-65f37028ae10-file-managerhigh · 8.8Cross-Site Request Forgery (CSRF)

Bit File Manager <= 4.1.4 - Cross-Site Request Forgery to Arbitrary File Upload

Mar 1, 2017 Patched in 4.1.5 (2519d)
Version History

File Manager Release Timeline

v6.9Current
v6.8.9
v6.8.8
v6.8.7
v6.8.6
v6.8.5
v6.8.4
v6.8.3
v6.8.2
v6.8.1
v6.8
v6.71 CVE
v6.6.31 CVE
v6.6.21 CVE
v6.6.11 CVE
v6.6.01 CVE
v6.5.81 CVE
Maintenance & Trust

File Manager Maintenance & Trust

Maintenance Signals

WordPress version tested7.0.2
Last updatedJul 7, 2026
PHP min version7.4
Downloads1.6M

Community Trust

Rating86/100
Number of ratings201
Active installs10K
Developer Profile

File Manager Developer Profile

Bit Apps

7 plugins · 60K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
169 days
View full developer profile
FAQ

Frequently Asked Questions about File Manager