The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and including, 18.2. This is due to lacking authentication protections and lacking a security nonce on the wpfm_delete_file AJAX action. This makes it possible for unauthenticated attackers to delete any posts and pages on the site.
References
Configurations
History
No history.
Information
Published : 2023-06-07 02:15
Updated : 2023-11-07 03:40
NVD link : CVE-2021-4359
Mitre link : CVE-2021-4359
CVE.ORG link : CVE-2021-4359
JSON object : View
Products Affected
najeebmedia
- frontend_file_manager_plugin
CWE
CWE-862
Missing Authorization