PT-2023-12479 · WordPress · Frontend File Manager

Jerome Bruandet

·

Published

2023-06-07

·

Updated

2023-06-13

·

CVE-2021-4368

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Frontend File Manager plugin for WordPress versions up to, and including, 18.2
Description The issue is related to lacking capability checks and a security nonce in the wpfm save settings AJAX action. This allows subscriber-level attackers to edit plugin settings, such as the allowed upload file types, potentially leading to remote code execution through other vulnerabilities.
Recommendations For versions up to, and including, 18.2, update to a version that includes the necessary capability checks and security nonce for the wpfm save settings AJAX action to prevent unauthorized changes to plugin settings.

Exploit

Fix

RCE

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2021-4368

Affected Products

Frontend File Manager