๐Ÿ” CVE Alert

CVE-2022-3125

UNKNOWN 0.0

Frontend File Manager < 21.3 - Subscriber+ Arbitrary File Upload

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Frontend File Manager Plugin WordPress plugin before 21.3 allows any authenticated users, such as subscriber, to rename a file to an arbitrary extension, like PHP, which could allow them to basically be able to upload arbitrary files on the server and achieve RCE

CWE CWE-434
Vendor unknown
Product frontend file manager plugin
Published Oct 3, 2022
Last Updated Aug 3, 2024
Stay Ahead of the Next One

Get instant alerts for unknown frontend file manager plugin

Be the first to know when new unknown vulnerabilities affecting unknown frontend file manager plugin are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Frontend File Manager Plugin
21.3 < 21.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/d3d9dc9a-226b-4f76-995e-e2af1dd6b17e

Credits

Raad Haddad of Cloudyrion GmbH