Unauthenticated Arbitrary Post Deletion in Frontend File Manager Plugin for WordPress
CVE-2021-4359
6.5MEDIUM
What is CVE-2021-4359?
The Frontend File Manager plugin for WordPress contains a security flaw that enables unauthenticated attackers to delete any posts and pages on the site. This issue arises from inadequate authentication mechanisms and the absence of a security nonce during the wpfm_delete_file AJAX action. As a result, anyone can exploit this vulnerability to remove content without requiring any user credentials, posing a serious risk to site integrity.
Affected Version(s)
Frontend File Manager Plugin * < 18.3