Unauthenticated Post Meta Change in Frontend File Manager Plugin for WordPress
CVE-2021-4351
5.8MEDIUM
Summary
The Frontend File Manager plugin for WordPress contains vulnerabilities that allow unauthenticated attackers to alter post meta data. This issue arises from insufficient authentication controls, inadequate capability checks, and lack of data sanitization specifically in the wpfm_file_meta_update AJAX action. The flaw affects versions up to and including 18.2, potentially exposing WordPress sites to unauthorized modifications of important content.
Affected Version(s)
Frontend File Manager Plugin * < 18.3
References
CVSS V3.1
Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jerome Bruandet