PT-2022-20633 · WordPress · Frontend File Manager Plugin
Raad Haddad
·
Published
2022-10-03
·
Updated
2026-06-07
·
CVE-2022-3124
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Frontend File Manager Plugin WordPress plugin versions prior to 21.3
Description
The issue allows any unauthenticated user to rename uploaded files from users. Due to the lack of validation in the destination filename, this could allow them to change the content of arbitrary files on the web server.
Recommendations
For versions prior to 21.3, update to version 21.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the file upload and rename functionality to authenticated users only. Avoid using the file rename feature until the issue is resolved.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Frontend File Manager Plugin