Unauthenticated Post Meta Change in Frontend File Manager Plugin for WordPress
CVE-2021-4351
5.8MEDIUM
What is CVE-2021-4351?
The Frontend File Manager plugin for WordPress contains vulnerabilities that allow unauthenticated attackers to alter post meta data. This issue arises from insufficient authentication controls, inadequate capability checks, and lack of data sanitization specifically in the wpfm_file_meta_update AJAX action. The flaw affects versions up to and including 18.2, potentially exposing WordPress sites to unauthorized modifications of important content.
Affected Version(s)
Frontend File Manager Plugin * < 18.3