Extension WordPress

Vulnérabilités Frontend File Manager Plugin, page 2

Cette page rassemble les failles publiées pour Frontend File Manager Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.

30Vulnérabilités
5Critiques
24Avec correctif
9,9CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Frontend File Manager Plugin

30 fiches

CVE-2021-4365 Élevée · 7,2
Frontend File Manager Plugin

Frontend File Manager <= 18.2 – Unauthenticated Stored Cross-Site Scripting

The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to, and including, 18.2. This is due to lacking authentication protections and santisation all on the wpfm_edit_file_title_desc AJAX action. This makes…

Versions affectées

[*, 18.3)

Correctif

18.3

Publication

12/07/2021

CVE-2021-4356 Critique · 9,0
Frontend File Manager Plugin

Frontend File Manager <= 18.2 – Unauthenticated Arbitrary File Download

The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Download in versions up to, and including, 18.2. This is due to lacking authentication protections, capability checks, and sanitization, all on the wpfm_file_meta_update AJAX action.…

Versions affectées

[*, 18.3)

Correctif

18.3

Publication

12/07/2021

CVE-2021-4350 Élevée · 7,2
Frontend File Manager Plugin

Frontend File Manager <= 18.2 – Unauthenticated HTML Injection leading to Spam Emails

The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated HTML Injection in versions up to, and including, 18.2. This is due to lacking authentication protections on the wpfm_send_file_in_email AJAX action. This makes it possible for unauthenticated…

Versions affectées

[*, 18.3)

Correctif

18.3

Publication

12/07/2021

CVE-2016-15042 Critique · 9,8
Frontend File Manager Plugin

Frontend File Manager < 4.0 & N-Media Post Front-end Form < 1.1 & – Arbitrary File Upload

The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulnerable to arbitrary file uploads due to missing file type validation via the `nm_filemanager_upload_file` and `nm_postfront_upload_file` AJAX actions. This makes…

Versions affectées

[*, 4.0)

Correctif

4.0

Publication

16/07/2016

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités