Unauthenticated Arbitrary File Download Vulnerability in Frontend File Manager Plugin for WordPress
CVE-2021-4356
9CRITICAL
What is CVE-2021-4356?
The Frontend File Manager plugin for WordPress is vulnerable due to insufficient authentication measures, lack of capability verification, and inadequate file sanitization in the wpfm_file_meta_update AJAX action. This allows attackers to exploit the vulnerability and download sensitive files from the server without any authentication. Consequently, this may lead to further security breaches and potential site takeover if sensitive data is accessed.
Affected Version(s)
Frontend File Manager Plugin * < 18.3