Authenticated Settings Change Vulnerability in Frontend File Manager Plugin for WordPress
CVE-2021-4368
9.9CRITICAL
Summary
The Frontend File Manager plugin for WordPress, prior to version 18.2, contains a vulnerability that permits authenticated users with subscriber-level access to modify critical plugin settings. This flaw arises from insufficient capability checks and the absence of a security nonce within the wpfm_save_settings AJAX action. Attackers can exploit this vulnerability to alter settings, such as permitted file types for uploads, potentially leading to remote code execution through related security gaps.
Affected Version(s)
Frontend File Manager Plugin * < 18.3
References
CVSS V3.1
Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jerome Bruandet