PT-2022-16075 · WordPress · Frontend File Manager & Sharing

Raad Haddad

·

Published

2022-08-08

·

Updated

2022-08-11

·

CVE-2022-2356

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Frontend File Manager & Sharing WordPress plugin versions prior to 1.1.3
Description The issue allows users to upload files without proper filtering of file extensions, potentially leading to the upload of malicious code.
Recommendations For versions prior to 1.1.3, update to version 1.1.3 or later to resolve the issue. As a temporary workaround, consider restricting file uploads to only necessary extensions to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2022-2356

Affected Products

Frontend File Manager & Sharing