Share
## https://sploitus.com/exploit?id=WPEX-ID:F250226F-4A05-4D75-93C4-5444A4CE919E
1. Go to settings page (/wordpress/wp-admin/admin.php?page=file-manager-settings).
2. In the “Root Folder Path” setting, change directory to /home or you can use Path Traversal /var/www/html/../../../home or /var/www/html/wordpress/../../../../etc.
3. Then navigate to the page of plugin (/wordpress/wp-admin/admin.php?page=file-manager#elf_l1_Lw).
4. You will be able to list the files/folders outside of the WordPress root directory.