The Frontend File Manager Plugin WordPress plugin before...
Moderate severity
Unreviewed
Published
Oct 4, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Oct 3, 2022
Published to the GitHub Advisory Database
Oct 4, 2022
Last updated
Jan 27, 2023
The Frontend File Manager Plugin WordPress plugin before 21.3 allows any unauthenticated user to rename uploaded files from users. Furthermore, due to the lack of validation in the destination filename, this could allow allow them to change the content of arbitrary files on the web server
References