Authenticated Settings Change Vulnerability in Frontend File Manager Plugin for WordPress
CVE-2021-4368
What is CVE-2021-4368?
The Frontend File Manager plugin for WordPress, prior to version 18.2, contains a vulnerability that permits authenticated users with subscriber-level access to modify critical plugin settings. This flaw arises from insufficient capability checks and the absence of a security nonce within the wpfm_save_settings AJAX action. Attackers can exploit this vulnerability to alter settings, such as permitted file types for uploads, potentially leading to remote code execution through related security gaps.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Frontend File Manager Plugin * < 18.3
References
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved