Najeebmedia
Najeebmedia Frontend File Manager Plugin: vulnerabilidades y CVE
Najeebmedia Frontend File Manager Plugin tiene 10 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-5105 | Media (6.5) | 1.0% | — | 4 dic 2023 | The Frontend File Manager Plugin WordPress plugin before 22.6 has a vulnerability that allows an Editor+ user to bypass the file download logic and download files such as `wp-config.php` |
| CVE-2021-4369 | Media (5.3) | 0.80% | — | 7 jun 2023 | The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Content Injection in versions up to, and including, 18.2. This is due to lacking authorization protections, checks against users editing… |
| CVE-2021-4368 | Alta (8.8) | 1.9% | — | 7 jun 2023 | The Frontend File Manager plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 18.2. This is due to lacking capability checks and a security nonce, all on the… |
| CVE-2021-4365 | Media (6.1) | 0.76% | — | 7 jun 2023 | The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to, and including, 18.2. This is due to lacking authentication protections and santisation all… |
| CVE-2021-4359 | Media (5.3) | 0.88% | — | 7 jun 2023 | The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and including, 18.2. This is due to lacking authentication protections and lacking a security… |
| CVE-2021-4356 | Crítica (9.8) | 1.5% | — | 7 jun 2023 | The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Download in versions up to, and including, 18.2. This is due to lacking authentication protections, capability checks, and… |
| CVE-2021-4351 | Media (5.3) | 0.68% | — | 7 jun 2023 | The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Post Meta Change in versions up to, and including, 18.2. This is due to lacking authentication protections, capability checks, and… |
| CVE-2021-4350 | Media (5.3) | 0.67% | — | 7 jun 2023 | The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated HTML Injection in versions up to, and including, 18.2. This is due to lacking authentication protections on the wpfm_send_file_in_email… |
| CVE-2021-4344 | Media (5.4) | 0.47% | — | 7 jun 2023 | The Frontend File Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 18.2. This is due to lacking mishandling the use of user IDs that is accessible by the visitor. This… |
| CVE-2022-3126 | Media (4.3) | 0.29% | — | 17 oct 2022 | The Frontend File Manager Plugin WordPress plugin before 21.4 does not have CSRF check when uploading files, which could allow attackers to make logged in users upload files on their behalf |
Otros productos de Najeebmedia
Frontend File Manager · 16Ppom FOR Woocommerce · 2Memberhero · 2Comments Extra Fields FOR Post, Pages AND CPT · 2Post Front-end Form · 1Website Contact Form With File Upload · 1Woocommerce Checkout Field Manager · 1Wordpress Comments Fields · 1Easy Quiz Maker · 1N-media File Uploader · 1Personalized Woocommerce Cart Page · 1