Najeebmedia

Frontend File Manager Plugin

10 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.48%
  • Veröffentlicht 04.12.2023 22:15:07
  • Zuletzt bearbeitet 21.11.2024 08:41:04

The Frontend File Manager Plugin WordPress plugin before 22.6 has a vulnerability that allows an Editor+ user to bypass the file download logic and download files such as `wp-config.php`

Exploit
  • EPSS 0.63%
  • Veröffentlicht 07.06.2023 02:15:14
  • Zuletzt bearbeitet 21.11.2024 06:37:29

The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Download in versions up to, and including, 18.2. This is due to lacking authentication protections, capability checks, and sanitization, all on the wpfm_...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 07.06.2023 02:15:14
  • Zuletzt bearbeitet 21.11.2024 06:37:30

The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and including, 18.2. This is due to lacking authentication protections and lacking a security nonce on the wpfm_delete_file AJA...

Exploit
  • EPSS 0.94%
  • Veröffentlicht 07.06.2023 02:15:14
  • Zuletzt bearbeitet 21.11.2024 06:37:30

The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to, and including, 18.2. This is due to lacking authentication protections and santisation all on the wpfm_edit_file_title_desc...

Exploit
  • EPSS 6.79%
  • Veröffentlicht 07.06.2023 02:15:14
  • Zuletzt bearbeitet 21.11.2024 06:37:31

The Frontend File Manager plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 18.2. This is due to lacking capability checks and a security nonce, all on the wpfm_save_settings AJAX action. This makes...

Exploit
  • EPSS 0.16%
  • Veröffentlicht 07.06.2023 02:15:14
  • Zuletzt bearbeitet 21.11.2024 06:37:31

The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Content Injection in versions up to, and including, 18.2. This is due to lacking authorization protections, checks against users editing other's posts, and lacking a secu...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 07.06.2023 02:15:13
  • Zuletzt bearbeitet 21.11.2024 06:37:27

The Frontend File Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 18.2. This is due to lacking mishandling the use of user IDs that is accessible by the visitor. This makes it possible for unauthen...

Exploit
  • EPSS 0.12%
  • Veröffentlicht 07.06.2023 02:15:13
  • Zuletzt bearbeitet 21.11.2024 06:37:28

The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated HTML Injection in versions up to, and including, 18.2. This is due to lacking authentication protections on the wpfm_send_file_in_email AJAX action. This makes it possibl...

Exploit
  • EPSS 0.18%
  • Veröffentlicht 07.06.2023 02:15:13
  • Zuletzt bearbeitet 21.11.2024 06:37:28

The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Post Meta Change in versions up to, and including, 18.2. This is due to lacking authentication protections, capability checks, and sanitization, all on the wpfm_file_meta...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 17.10.2022 12:15:10
  • Zuletzt bearbeitet 14.05.2025 16:15:21

The Frontend File Manager Plugin WordPress plugin before 21.4 does not have CSRF check when uploading files, which could allow attackers to make logged in users upload files on their behalf