N-Media Post Front-end Form [wp-post-frontend] < 1.1
unknown
[en] The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulnerable to arbitrary file uploads due to missing file type validation via the `nm_filemanager_upload_file` and `nm_postfront_upload_file` AJAX actions. This makes it possible for unauthenticated at...
- Affected:
- up to 1.1
- Fixed in:
- 1.1
- Disclosed:
- Oct 16, 2024
CVE-2016-15042 on NVD →
N-Media Post Front-end Form [wp-post-frontend] < 1.1
unknown
Arbitrary File Upload Vulnerability was found in WordPress N-Media Post Front-end Form Plugin v1.0. It only validates the file on client-side with JavaScript so the validation can be easily bypassed.
Update the plugin.
- Affected:
- up to 1.1
- Fixed in:
- 1.1
- Disclosed:
- Sep 19, 2016
Frontend File Manager < 4.0 & N-Media Post Front-end Form < 1.1 & - Arbitrary File Upload
critical
The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulnerable to arbitrary file uploads due to missing file type validation via the `nm_filemanager_upload_file` and `nm_postfront_upload_file` AJAX actions. This makes it possible for unauthenticated attacke...
- CVSS:
- 9.8
- Affected:
- up to 1.0
- Fixed in:
- 1.1
- Disclosed:
- Jul 16, 2016
CVE-2016-15042 on NVD →
N-Media Post Front-end Form [wp-post-frontend] < 1.1
unknown
The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulnerable to arbitrary file uploads due to missing file type validation via the `nm_filemanager_upload_file` and `nm_postfront_upload_file` AJAX actions. This makes it possible for unauthenticated attacke...
- Affected:
- up to 1.1
- Fixed in:
- 1.1
- Disclosed:
- Jul 16, 2016
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database