• I installed wp-FileManager plugin thinking it would be an easy way for my client to overwrite a file that is being parsed on the site, which it was. but when playing with the plugin I noticed if I put the path to / and turn on all permissions, I can delete, modify, create any file I want down to the root directory of my Server not just my wp install.

    This seams a bit crazy, as with admin access to a WP install anyone could now install this plugin and delete files from other sites on that server, or server files themselves.

    My question I guess is, what permissions is this plugin using to remove files if any? and is there a way through my Cpanel or something to prevent this level of access through the WP-admin panel?

The topic ‘WP-FileManager security question’ is closed to new replies.