The WordPress File Manager plugin prior to version 6.9 is susceptible to remote code execution. The vulnerability allows unauthenticated remote attackers to upload .php files.
id: CVE-2020-25213
# Uploaded file will be accessible at:-
# http://localhost/wp-content/plugins/wp
...