First published: Wed Jun 07 2023(Updated: )
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and including, 18.2. This is due to lacking authentication protections and lacking a security nonce on the wpfm_delete_file AJAX action. This makes it possible for unauthenticated attackers to delete any posts and pages on the site.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
N-Media Frontend File Manager | <=18.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-4359 is a vulnerability in the Frontend File Manager plugin for WordPress that allows unauthenticated users to delete posts on a vulnerable site.
The severity of CVE-2021-4359 is medium with a CVSS score of 5.3.
CVE-2021-4359 affects the Frontend File Manager plugin by allowing unauthenticated users to delete posts without proper authentication and security nonce protection.
Versions up to and including 18.2 of the Frontend File Manager plugin are affected by CVE-2021-4359.
Yes, there is a fix available for CVE-2021-4359. It is recommended to update to a version of the Frontend File Manager plugin that includes the necessary security fixes.