Unauthenticated Post Meta Change in Frontend File Manager Plugin for WordPress
CVE-2021-4351

5.8MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
7 June 2023

Summary

The Frontend File Manager plugin for WordPress contains vulnerabilities that allow unauthenticated attackers to alter post meta data. This issue arises from insufficient authentication controls, inadequate capability checks, and lack of data sanitization specifically in the wpfm_file_meta_update AJAX action. The flaw affects versions up to and including 18.2, potentially exposing WordPress sites to unauthorized modifications of important content.

Affected Version(s)

Frontend File Manager Plugin * < 18.3

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jerome Bruandet
.