CVE-2020-35235: Themexa Secure File Manager

High severity, CVSS 8.8. EPSS: 18.3% chance of exploitation in the next 30 days.

vendor/elfinder/php/connector.minimal.php in the secure-file-manager plugin through 2.5 for WordPress loads elFinder code without proper access control. Thus, any authenticated user can run the elFinder upload command to achieve remote code execution. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

Affected products

  • Themexa Secure File Manager: up to and including 2.5

Published 2020-12-14. Last modified 2026-06-17.