Frontend File Manager <= 23.6 - Unauthenticated Arbitrary File Deletion
critical
The Frontend File Manager Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 23.6. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution...
- CVSS:
- 9.1
- Affected:
- up to 23.6
- Fix:
- No patched version reported
- Disclosed:
- Aug 16, 2026
CVE-2026-12277 on NVD →
Frontend File Manager Plugin <= 23.6 - Cross-Site Request Forgery
medium
The Frontend File Manager Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 23.6. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request grante...
- CVSS:
- 4.3
- Affected:
- up to 23.6
- Fix:
- No patched version reported
- Disclosed:
- Aug 2, 2026
CVE-2026-16292 on NVD →
Frontend File Manager Plugin <= 23.6 - Authenticated (Subscriber+) Arbitrary File Deletion
high
The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions up to and including 23.6. This is due to a case-sensitive bypass of the wpfm_dir_path parameter sanitization in the wpfm_file_meta_update AJAX handler, where supplying WPFM_DIR_PATH in uppercase evad...
- CVSS:
- 8.1
- Affected:
- up to 23.6
- Fix:
- No patched version reported
- Disclosed:
- Jun 27, 2026
CVE-2026-8095 on NVD →
Frontend File Manager Plugin <= 23.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The Frontend File Manager Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 23.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web script...
- CVSS:
- 6.4
- Affected:
- up to 23.6
- Fix:
- No patched version reported
- Disclosed:
- Jun 25, 2026
CVE-2026-8378 on NVD →
Frontend File Manager Plugin <= 23.6 - Missing Authorization to Unauthenticated File Download
medium
The Frontend File Manager Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'wpfm_download' action in all versions up to, and including, 23.6. This makes it possible for unauthenticated attackers to download files from the plugin.
- CVSS:
- 5.3
- Affected:
- up to 23.6
- Fix:
- No patched version reported
- Disclosed:
- Jun 25, 2026
CVE-2026-8379 on NVD →
Frontend File Manager <= 23.6 - Missing Authorization to Authenticated (Author+) Arbitrary Post Deletion
medium
The Frontend File Manager Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 23.6. This makes it possible for authenticated attackers, with Author-level access and above, to delete arbitrary posts.
- CVSS:
- 4.3
- Affected:
- up to 23.6
- Fix:
- No patched version reported
- Disclosed:
- Jun 4, 2026
CVE-2026-8380 on NVD →
Frontend File Manager <= 23.6 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Download Access
medium
The Frontend File Manager Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 23.6 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to download arbitrary file do...
- CVSS:
- 4.3
- Affected:
- up to 23.6
- Fix:
- No patched version reported
- Disclosed:
- Apr 11, 2026
CVE-2026-5337 on NVD →
Frontend File Manager Plugin [nmedia-user-file-uploader] <= 23.5 (unfixed)
unknown
[en] Authorization Bypass Through User-Controlled Key vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Frontend File Manager: from n/a through <= 23.5.
- Affected:
- up to 23.5
- Fix:
- No patched version reported
- Disclosed:
- Feb 19, 2026
CVE-2026-25005 on NVD →
Frontend File Manager <= 23.5 - Missing Authorization
medium
The Frontend File Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 23.5. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 23.5
- Fix:
- No patched version reported
- Disclosed:
- Feb 17, 2026
CVE-2026-0829 on NVD →
Frontend File Manager Plugin <= 23.5 - Missing Authorization to Unauthenticated Arbitrary File Sharing via 'file_id' Parameter
high
The Frontend File Manager Plugin for WordPress is vulnerable to unauthorized file sharing due to a missing capability check on the 'wpfm_send_file_in_email' AJAX action in all versions up to, and including, 23.5. This makes it possible for unauthenticated attackers to share arbitrary uploaded files via email by supplyi...
- CVSS:
- 7.5
- Affected:
- up to 23.5
- Fixed in:
- 23.6
- Disclosed:
- Jan 27, 2026
CVE-2026-1280 on NVD →
Frontend File Manager Plugin <= 23.5 - Unauthenticated Insecure Direct Object Reference
medium
The Frontend File Manager Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 23.5 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 23.5
- Fixed in:
- 23.6
- Disclosed:
- Jan 16, 2026
CVE-2026-25005 on NVD →
Frontend File Manager Plugin [nmedia-user-file-uploader] < 23.5
unknown
[en] The Frontend File Manager Plugin WordPress plugin before 23.5 did not validate a path parameter and ownership of the file, allowing any authenticated users, such as subscribers to delete arbitrary files on the server
- Affected:
- up to 23.5
- Fixed in:
- 23.5
- Disclosed:
- Jan 7, 2026
CVE-2025-14804 on NVD →
Frontend File Manager <= 23.4 - Authenticated (Subscriber+) Arbitrary File Deletion
high
The Frontend File Manager Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 23.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which c...
- CVSS:
- 8.1
- Affected:
- up to 23.4
- Fixed in:
- 23.5
- Disclosed:
- Dec 17, 2025
CVE-2025-14804 on NVD →
Frontend File Manager Plugin [nmedia-user-file-uploader] <= 23.4 (unfixed)
unknown
[en] The Frontend File Manager Plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 23.4. This is due to the plugin not validating file ownership before processing file rename requests in the '/wpfm/v1/file-rename' REST API endpoint. This makes it possible for aut...
- Affected:
- up to 23.4
- Fix:
- No patched version reported
- Disclosed:
- Nov 25, 2025
CVE-2025-13382 on NVD →
Frontend File Manager Plugin <= 23.4 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary File Renaming
medium
The Frontend File Manager Plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 23.4. This is due to the plugin not validating file ownership before processing file rename requests in the '/wpfm/v1/file-rename' REST API endpoint. This makes it possible for authenti...
- CVSS:
- 4.3
- Affected:
- up to 23.4
- Fixed in:
- 23.5
- Disclosed:
- Nov 24, 2025
CVE-2025-13382 on NVD →
Frontend File Manager Plugin [nmedia-user-file-uploader] < 23.3
unknown
[en] Missing Authorization vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Frontend File Manager: from n/a through <= 23.2.
- Affected:
- up to 23.3
- Fixed in:
- 23.3
- Disclosed:
- Nov 13, 2025
CVE-2025-64265 on NVD →
Frontend File Manager <= 23.2 - Missing Authorization
medium
The Frontend File Manager Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 23.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 23.2
- Fixed in:
- 23.3
- Disclosed:
- Oct 30, 2025
CVE-2025-64265 on NVD →
Frontend File Manager <= 23.2 - Missing Authorization
medium
The Frontend File Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 23.2. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 23.2
- Fixed in:
- 23.4
- Disclosed:
- Sep 22, 2025
CVE-2025-57921 on NVD →
Frontend File Manager <= 21.5 - Missing Authorization to Unauthenticated Arbitrary Post Deletion
high
The Frontend File Manager Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wpfm_delete_multiple_files() function in all versions up to, and including, 21.5. This makes it possible for unauthenticated attackers to delete arbitrary posts.
- CVSS:
- 7.5
- Affected:
- up to 21.5
- Fixed in:
- 22.0
- Disclosed:
- Jul 24, 2025
CVE-2023-7306 on NVD →
Frontend File Manager <= 23.2 - Missing Authorization to Authenticated (Subscriber+) Content Injection
medium
The Frontend File Manager Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 23.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject content.
- CVSS:
- 4.3
- Affected:
- up to 23.2
- Fix:
- No patched version reported
- Disclosed:
- Jul 4, 2025
CVE-2025-27358 on NVD →
Frontend File Manager Plugin [nmedia-user-file-uploader] <= 23.2 (unfixed)
unknown
[en] Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in N-Media Frontend File Manager allows Code Injection.This issue affects Frontend File Manager: from n/a through 23.2.
- Affected:
- up to 23.2
- Fix:
- No patched version reported
- Disclosed:
- Jul 4, 2025
CVE-2025-27358 on NVD →
Frontend File Manager Plugin [nmedia-user-file-uploader] < 4.0
unknown
[en] The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulnerable to arbitrary file uploads due to missing file type validation via the `nm_filemanager_upload_file` and `nm_postfront_upload_file` AJAX actions. This makes it possible for unauthenticated at...
- Affected:
- up to 4.0
- Fixed in:
- 4.0
- Disclosed:
- Oct 16, 2024
CVE-2016-15042 on NVD →
Frontend File Manager Plugin [nmedia-user-file-uploader] < 22.8
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in N-Media Frontend File Manager.This issue affects Frontend File Manager: from n/a through 22.7.
- Affected:
- up to 22.8
- Fixed in:
- 22.8
- Disclosed:
- Mar 17, 2024
CVE-2024-25903 on NVD →
Frontend File Manager <= 22.7 - Sensitive Information Exposure via user uploads
medium
The Frontend File Manager Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 22.7 via the user upload functionality. This makes it possible for unauthenticated attackers to access user-uploaded files.
- CVSS:
- 5.3
- Affected:
- up to 22.7
- Fixed in:
- 22.8
- Disclosed:
- Feb 12, 2024
CVE-2024-25903 on NVD →
Frontend File Manager Plugin [nmedia-user-file-uploader] < 22.7
unknown
[en] The Frontend File Manager Plugin WordPress plugin before 22.6 has a vulnerability that allows an Editor+ user to bypass the file download logic and download files such as `wp-config.php`
- Affected:
- up to 22.7
- Fixed in:
- 22.7
- Disclosed:
- Dec 4, 2023
CVE-2023-5105 on NVD →
Frontend File Manager Plugin <= 22.5 - Authenticated (Editor+) Directory Traversal
critical
The Frontend File Manager Plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 22.5. This makes it possible for authenticated attackers, with editor access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
- CVSS:
- 9.1
- Affected:
- up to 22.5
- Fixed in:
- 22.6
- Disclosed:
- Nov 13, 2023
CVE-2023-5105 on NVD →
Frontend File Manager Plugin [nmedia-user-file-uploader] < 18.3
unknown
[en] The Frontend File Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 18.2. This is due to lacking mishandling the use of user IDs that is accessible by the visitor. This makes it possible for unauthenticated or authenticated attackers to access the information and...
- Affected:
- up to 18.3
- Fixed in:
- 18.3
- Disclosed:
- Jun 7, 2023
CVE-2021-4344 on NVD →
Frontend File Manager Plugin [nmedia-user-file-uploader] < 18.3
unknown
[en] The Frontend File Manager plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 18.2. This is due to lacking capability checks and a security nonce, all on the wpfm_save_settings AJAX action. This makes it possible for subscriber-level attackers to edit the plugin se...
- Affected:
- up to 18.3
- Fixed in:
- 18.3
- Disclosed:
- Jun 7, 2023
CVE-2021-4368 on NVD →
Frontend File Manager Plugin [nmedia-user-file-uploader] < 18.3
unknown
[en] The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Content Injection in versions up to, and including, 18.2. This is due to lacking authorization protections, checks against users editing other's posts, and lacking a security nonce, all on the wpfm_edit_file_title_desc AJAX action. Thi...
- Affected:
- up to 18.3
- Fixed in:
- 18.3
- Disclosed:
- Jun 7, 2023
CVE-2021-4369 on NVD →
Frontend File Manager Plugin [nmedia-user-file-uploader] < 18.3
unknown
[en] The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Post Meta Change in versions up to, and including, 18.2. This is due to lacking authentication protections, capability checks, and sanitization, all on the wpfm_file_meta_update AJAX action. This makes it possible for unauthenticated a...
- Affected:
- up to 18.3
- Fixed in:
- 18.3
- Disclosed:
- Jun 7, 2023
CVE-2021-4351 on NVD →
Frontend File Manager Plugin [nmedia-user-file-uploader] < 18.3
unknown
[en] The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Download
in versions up to, and including, 18.2. This is due to lacking authentication protections, capability checks, and sanitization, all on the wpfm_file_meta_update AJAX action. This makes it possible for unauthen...
- Affected:
- up to 18.3
- Fixed in:
- 18.3
- Disclosed:
- Jun 7, 2023
CVE-2021-4356 on NVD →
Frontend File Manager Plugin [nmedia-user-file-uploader] < 18.3
unknown
[en] The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to, and including, 18.2. This is due to lacking authentication protections and santisation all on the wpfm_edit_file_title_desc AJAX action. This makes it possible for unauthenticated attacker...
- Affected:
- up to 18.3
- Fixed in:
- 18.3
- Disclosed:
- Jun 7, 2023
CVE-2021-4365 on NVD →
Frontend File Manager Plugin [nmedia-user-file-uploader] < 18.3
unknown
[en] The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and including, 18.2. This is due to lacking authentication protections and lacking a security nonce on the wpfm_delete_file AJAX action. This makes it possible for unauthenticated attackers to...
- Affected:
- up to 18.3
- Fixed in:
- 18.3
- Disclosed:
- Jun 7, 2023
CVE-2021-4359 on NVD →
Frontend File Manager Plugin [nmedia-user-file-uploader] < 18.3
unknown
[en] The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated HTML Injection in versions up to, and including, 18.2. This is due to lacking authentication protections on the wpfm_send_file_in_email AJAX action. This makes it possible for unauthenticated attackers to send emails using the site wit...
- Affected:
- up to 18.3
- Fixed in:
- 18.3
- Disclosed:
- Jun 7, 2023
CVE-2021-4350 on NVD →
Frontend File Manager Plugin [nmedia-user-file-uploader] < 21.4
unknown
[en] The Frontend File Manager Plugin WordPress plugin before 21.4 does not have CSRF check when uploading files, which could allow attackers to make logged in users upload files on their behalf
- Affected:
- up to 21.4
- Fixed in:
- 21.4
- Disclosed:
- Oct 17, 2022
CVE-2022-3126 on NVD →
Frontend File Manager Plugin [nmedia-user-file-uploader] < 21.3
unknown
[en] The Frontend File Manager Plugin WordPress plugin before 21.3 allows any authenticated users, such as subscriber, to rename a file to an arbitrary extension, like PHP, which could allow them to basically be able to upload arbitrary files on the server and achieve RCE
- Affected:
- up to 21.3
- Fixed in:
- 21.3
- Disclosed:
- Oct 3, 2022
CVE-2022-3125 on NVD →
Frontend File Manager Plugin [nmedia-user-file-uploader] < 21.3
unknown
[en] The Frontend File Manager Plugin WordPress plugin before 21.3 allows any unauthenticated user to rename uploaded files from users. Furthermore, due to the lack of validation in the destination filename, this could allow allow them to change the content of arbitrary files on the web server
- Affected:
- up to 21.3
- Fixed in:
- 21.3
- Disclosed:
- Oct 3, 2022
CVE-2022-3124 on NVD →
Frontend File Manager Plugin <= 21.2 - Cross-Site Request Forgery to File Upload
high
The "Frontend File Manager Plugin" plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 21.2. This is due to missing or incorrect nonce validation on the wpfm_upload_file function. This makes it possible for unauthenticated attackers to upload files on behalf of other users...
- CVSS:
- 8.8
- Affected:
- up to 21.2
- Fixed in:
- 21.3
- Disclosed:
- Sep 26, 2022
CVE-2022-3126 on NVD →
Frontend File Manager Plugin [nmedia-user-file-uploader] < 21.4
unknown
Arbitrary Settings Update via Cross-Site Request Forgery (CSRF) vulnerability discovered by WPScan in WordPress Frontend File Manager plugin (versions <= 21.3)
Update the WordPress Frontend File Manager plugin to the latest available version (at least 21.4).
- Affected:
- up to 21.4
- Fixed in:
- 21.4
- Disclosed:
- Sep 26, 2022
Frontend File Manager <= 21.2 - Authenticated (Subscriber+) Arbitrary File Upload
high
The Frontend File Manager plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 21.2. The vulnerability makes it possible for authenticated attackers, with subscriber-level permissions and above, to upload arbitrary files on the affected sites server and change their file extens...
- CVSS:
- 8.8
- Affected:
- up to 21.2
- Fixed in:
- 21.3
- Disclosed:
- Sep 7, 2022
CVE-2022-3125 on NVD →
Frontend File Manager <= 21.2 - Missing Authorization
medium
The Frontend File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check and lacking authentication in versions up to, and including, 21.2. This makes it possible for unauthenticated attackers to rename uploaded files on the site.
- CVSS:
- 6.5
- Affected:
- up to 21.2
- Fixed in:
- 21.3
- Disclosed:
- Sep 7, 2022
CVE-2022-3124 on NVD →
Frontend File Manager <= 21.3 - Cross-Site Request Forgery to Plugin Settings Update
high
The Frontend File Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 21.3. This is due to missing or incorrect nonce validation on the wpfm_save_settings function. This makes it possible for unauthenticated attackers to modify the plugin's settings, via forged req...
- CVSS:
- 8.8
- Affected:
- up to 21.3
- Fixed in:
- 21.4
- Disclosed:
- Sep 6, 2022
Frontend File Manager Plugin [nmedia-user-file-uploader] < 21.3
unknown
The Frontend File Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 21.3. This is due to missing or incorrect nonce validation on the wpfm_save_settings function. This makes it possible for unauthenticated attackers to modify the plugin's settings, via forged req...
- Affected:
- up to 21.3
- Fixed in:
- 21.3
- Disclosed:
- Sep 6, 2022
Frontend File Manager <= 18.2 - Authenticated Settings Change leading to Arbitrary File Upload
critical
The Frontend File Manager plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 18.2. This is due to lacking capability checks and a security nonce, all on the wpfm_save_settings AJAX action. This makes it possible for subscriber-level attackers to edit the plugin setting...
- CVSS:
- 9.9
- Affected:
- up to 18.3
- Fixed in:
- 18.3
- Disclosed:
- Jul 12, 2021
CVE-2021-4368 on NVD →
Frontend File Manager <= 18.2 - Unauthenticated Arbitrary File Download
critical
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Download
in versions up to, and including, 18.2. This is due to lacking authentication protections, capability checks, and sanitization, all on the wpfm_file_meta_update AJAX action. This makes it possible for unauthenticat...
- CVSS:
- 9
- Affected:
- up to 18.3
- Fixed in:
- 18.3
- Disclosed:
- Jul 12, 2021
CVE-2021-4356 on NVD →
Frontend File Manager <= 18.2 - Unauthenticated HTML Injection leading to Spam Emails
high
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated HTML Injection in versions up to, and including, 18.2. This is due to lacking authentication protections on the wpfm_send_file_in_email AJAX action. This makes it possible for unauthenticated attackers to send emails using the site with a c...
- CVSS:
- 7.2
- Affected:
- up to 18.3
- Fixed in:
- 18.3
- Disclosed:
- Jul 12, 2021
CVE-2021-4350 on NVD →
Frontend File Manager <= 18.2 - Unauthenticated Stored Cross-Site Scripting
high
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to, and including, 18.2. This is due to lacking authentication protections and santisation all on the wpfm_edit_file_title_desc AJAX action. This makes it possible for unauthenticated attackers to...
- CVSS:
- 7.2
- Affected:
- up to 18.3
- Fixed in:
- 18.3
- Disclosed:
- Jul 12, 2021
CVE-2021-4365 on NVD →
Frontend File Manager Plugin <= 18.2 - Unauthenticated Arbitrary Post Deletion
medium
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and including, 18.2. This is due to lacking authentication protections and lacking a security nonce on the wpfm_delete_file AJAX action. This makes it possible for unauthenticated attackers to dele...
- CVSS:
- 6.5
- Affected:
- up to 18.3
- Fixed in:
- 18.3
- Disclosed:
- Jul 12, 2021
CVE-2021-4359 on NVD →
Frontend File Manager <= 18.2 - Privilege Escalation
medium
The Frontend File Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 18.2. This is due to lacking mishandling the use of user IDs that is accessible by the visitor. This makes it possible for unauthenticated or authenticated attackers to access the information and privi...
- CVSS:
- 6.4
- Affected:
- up to 18.3
- Fixed in:
- 18.3
- Disclosed:
- Jul 12, 2021
CVE-2021-4344 on NVD →
Frontend File Manager <= 18.2 - Unauthenticated Content Injection
medium
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Content Injection in versions up to, and including, 18.2. This is due to lacking authorization protections, checks against users editing other's posts, and lacking a security nonce, all on the wpfm_edit_file_title_desc AJAX action. This mak...
- CVSS:
- 5.8
- Affected:
- up to 18.3
- Fixed in:
- 18.3
- Disclosed:
- Jul 12, 2021
CVE-2021-4369 on NVD →
Frontend File Manager <= 18.2 - Unauthenticated Post Meta Change
medium
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Post Meta Change in versions up to, and including, 18.2. This is due to lacking authentication protections, capability checks, and sanitization, all on the wpfm_file_meta_update AJAX action. This makes it possible for unauthenticated attack...
- CVSS:
- 5.8
- Affected:
- up to 18.3
- Fixed in:
- 18.3
- Disclosed:
- Jul 12, 2021
CVE-2021-4351 on NVD →
Frontend File Manager Plugin [nmedia-user-file-uploader] < 18.3
unknown
The Frontend File Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 18.2. This is due to lacking mishandling the use of user IDs that is accessible by the visitor. This makes it possible for unauthenticated or authenticated attackers to access the information and privi...
- Affected:
- up to 18.3
- Fixed in:
- 18.3
- Disclosed:
- Jul 12, 2021
Frontend File Manager Plugin [nmedia-user-file-uploader] < 18.3
unknown
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Content Injection in versions up to, and including, 18.2. This is due to lacking authorization protections, checks against users editing other's posts, and lacking a security nonce, all on the wpfm_edit_file_title_desc AJAX action. This mak...
- Affected:
- up to 18.3
- Fixed in:
- 18.3
- Disclosed:
- Jul 12, 2021
Frontend File Manager Plugin [nmedia-user-file-uploader] < 18.3
unknown
The Frontend File Manager plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 18.2. This is due to lacking capability checks and a security nonce, all on the wpfm_save_settings AJAX action. This makes it possible for subscriber-level attackers to edit the plugin setting...
- Affected:
- up to 18.3
- Fixed in:
- 18.3
- Disclosed:
- Jul 12, 2021
Frontend File Manager Plugin [nmedia-user-file-uploader] < 18.3
unknown
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to, and including, 18.2. This is due to lacking authentication protections and santisation all on the wpfm_edit_file_title_desc AJAX action. This makes it possible for unauthenticated attackers to...
- Affected:
- up to 18.3
- Fixed in:
- 18.3
- Disclosed:
- Jul 12, 2021
Frontend File Manager Plugin [nmedia-user-file-uploader] < 18.3
unknown
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and including, 18.2. This is due to lacking authentication protections and lacking a security nonce on the wpfm_delete_file AJAX action. This makes it possible for unauthenticated attackers to dele...
- Affected:
- up to 18.3
- Fixed in:
- 18.3
- Disclosed:
- Jul 12, 2021
Frontend File Manager Plugin [nmedia-user-file-uploader] < 18.0
unknown
Privilege Escalation vulnerability discovered by Jerome Bruandet (NinTechNet) in WordPress Frontend File Manager plugin (versions <= 17.1).
- Affected:
- up to 18.0
- Fixed in:
- 18.0
- Disclosed:
- Jul 12, 2021
Frontend File Manager Plugin [nmedia-user-file-uploader] < 18.3
unknown
Unauthenticated Content Injection and Stored XSS vulnerabilities discovered by Jerome Bruandet (NinTechNet) in WordPress Frontend File Manager plugin (versions <= 18.2).
- Affected:
- up to 18.3
- Fixed in:
- 18.3
- Disclosed:
- Jul 12, 2021
Frontend File Manager Plugin [nmedia-user-file-uploader] < 18.3
unknown
Authenticated Settings Change and Arbitrary File Upload vulnerabilities discovered by Jerome Bruandet (NinTechNet) in WordPress Frontend File Manager plugin (versions <= 18.2).
- Affected:
- up to 18.3
- Fixed in:
- 18.3
- Disclosed:
- Jul 12, 2021
Frontend File Manager Plugin [nmedia-user-file-uploader] < 18.3
unknown
Unauthenticated HTML Injection vulnerability discovered by Jerome Bruandet (NinTechNet) in WordPress Frontend File Manager plugin (versions <= 18.2).
- Affected:
- up to 18.3
- Fixed in:
- 18.3
- Disclosed:
- Jul 12, 2021
Frontend File Manager Plugin [nmedia-user-file-uploader] < 18.3
unknown
Unauthenticated Post Meta Change and Arbitrary File Download vulnerability discovered by Jerome Bruandet (NinTechNet) in WordPress Frontend File Manager plugin (versions <= 18.2).
- Affected:
- up to 18.3
- Fixed in:
- 18.3
- Disclosed:
- Jul 12, 2021
Frontend File Manager Plugin [nmedia-user-file-uploader] < 18.3
unknown
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Download
in versions up to, and including, 18.2. This is due to lacking authentication protections, capability checks, and sanitization, all on the wpfm_file_meta_update AJAX action. This makes it possible for unauthenticat...
- Affected:
- up to 18.3
- Fixed in:
- 18.3
- Disclosed:
- Jul 12, 2021
Frontend File Manager Plugin [nmedia-user-file-uploader] < 18.3
unknown
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Post Meta Change in versions up to, and including, 18.2. This is due to lacking authentication protections, capability checks, and sanitization, all on the wpfm_file_meta_update AJAX action. This makes it possible for unauthenticated attack...
- Affected:
- up to 18.3
- Fixed in:
- 18.3
- Disclosed:
- Jul 12, 2021
Frontend File Manager Plugin [nmedia-user-file-uploader] < 18.3
unknown
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated HTML Injection in versions up to, and including, 18.2. This is due to lacking authentication protections on the wpfm_send_file_in_email AJAX action. This makes it possible for unauthenticated attackers to send emails using the site with a c...
- Affected:
- up to 18.3
- Fixed in:
- 18.3
- Disclosed:
- Jul 12, 2021
Frontend File Manager Plugin [nmedia-user-file-uploader] < 18.3
unknown
Unauthenticated Arbitrary Post Deletion vulnerability discovered by Jerome Bruandet (NinTechNet) in WordPress Frontend File Manager plugin (versions <= 18.2).
- Affected:
- up to 18.3
- Fixed in:
- 18.3
- Disclosed:
- Jul 12, 2021
Frontend File Manager Plugin [nmedia-user-file-uploader] < 4.0
unknown
This plugin is prone to an arbitrary file upload vulnerability.
Update the plugin.
- Affected:
- up to 4.0
- Fixed in:
- 4.0
- Disclosed:
- Sep 19, 2016
Frontend File Manager < 4.0 & N-Media Post Front-end Form < 1.1 & - Arbitrary File Upload
critical
The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulnerable to arbitrary file uploads due to missing file type validation via the `nm_filemanager_upload_file` and `nm_postfront_upload_file` AJAX actions. This makes it possible for unauthenticated attacke...
- CVSS:
- 9.8
- Affected:
- up to 4.0
- Fixed in:
- 4.0
- Disclosed:
- Jul 16, 2016
CVE-2016-15042 on NVD →
Frontend File Manager Plugin [nmedia-user-file-uploader] < 4.0
unknown
The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulnerable to arbitrary file uploads due to missing file type validation via the `nm_filemanager_upload_file` and `nm_postfront_upload_file` AJAX actions. This makes it possible for unauthenticated attacke...
- Affected:
- up to 4.0
- Fixed in:
- 4.0
- Disclosed:
- Jul 16, 2016
Frontend File Manager Plugin [nmedia-user-file-uploader] < 2.0
unknown
This plugin is prone to an arbitrary file upload vulnerability.
Update the plugin.
- Affected:
- up to 2.0
- Fixed in:
- 2.0
- Disclosed:
- Jun 11, 2015
Frontend File Manager Plugin [nmedia-user-file-uploader] < 3.8
unknown
This plugin is prone to an arbitrary file upload vulnerability.
Update the plugin.
- Affected:
- up to 3.8
- Fixed in:
- 3.8
- Disclosed:
- Jun 11, 2015
Frontend File Manager <= 3.7 - Arbitrary File Upload
critical
The Frontend File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in versions up to, and including, 3.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
- CVSS:
- 9.8
- Affected:
- up to 3.7
- Fixed in:
- 3.8
- Disclosed:
- Jun 10, 2015
Frontend File Manager Plugin [nmedia-user-file-uploader] < 3.8
unknown
The Frontend File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in versions up to, and including, 3.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
- Affected:
- up to 3.8
- Fixed in:
- 3.8
- Disclosed:
- Jun 10, 2015
Frontend File Manager Plugin [nmedia-user-file-uploader] < 3.6
unknown
[en] Unrestricted file upload vulnerability in the N-Media file uploader plugin before 3.4 for WordPress allows remote authenticated users to execute arbitrary PHP code by leveraging Author privileges to store a file.
- Affected:
- up to 3.6
- Fixed in:
- 3.6
- Disclosed:
- Sep 26, 2014
CVE-2014-5324 on NVD →
Frontend File Manager Plugin < 3.6 - Arbitrary File Upload
high
The Frontend File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the _template_uploader.php file in versions up to, and including, 3.5. This makes it possible for authenticated attackers, with author-level permissions and above, to upload arbitrary files on t...
- CVSS:
- 8.8
- Affected:
- up to 3.6
- Fixed in:
- 3.6
- Disclosed:
- Sep 25, 2014
CVE-2014-5324 on NVD →
Frontend File Manager Plugin [nmedia-user-file-uploader] < 22.0
unknown
- Affected:
- up to 22.0
- Fixed in:
- 22.0
CVE-2023-7306 on NVD →
Frontend File Manager Plugin [nmedia-user-file-uploader] < 21.4
unknown
The plugin does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. As the plugin does not validate the allowed file type, this could lead to attackers making admins allowing PHP file to be uploaded by any authenticated users
- Affected:
- up to 21.4
- Fixed in:
- 21.4
Frontend File Manager Plugin [nmedia-user-file-uploader] < 2.0
unknown
The Frontend File Manager Plugin WordPress plugin was affected by security vulnerability.
- Affected:
- up to 2.0
- Fixed in:
- 2.0
Frontend File Manager Plugin [nmedia-user-file-uploader] < 3.8
unknown
The Frontend File Manager Plugin WordPress plugin was affected by an Arbitrary File Upload security vulnerability.
- Affected:
- up to 3.8
- Fixed in:
- 3.8
Frontend File Manager Plugin [nmedia-user-file-uploader] < 3.8
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 3.8
- Fixed in:
- 3.8
CVE-2015-4693 on NVD →
Frontend File Manager Plugin [nmedia-user-file-uploader] < 4.0
unknown
The Frontend File Manager Plugin WordPress plugin was affected by an Arbitrary File Upload security vulnerability.
- Affected:
- up to 4.0
- Fixed in:
- 4.0