CVE-2021-4359: Frontend File Manager Plugin <= 18.2 - Unauthenticated Arbitrary Post Deletion
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and including, 18.2. This is due to lacking authentication protections and lacking a security nonce on the wpfmdeletefile AJAX action. This makes it possible for unauthenticated attackers to delete any posts and pages on the site.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-4359?
CVE-2021-4359 is a vulnerability in the Frontend File Manager plugin for WordPress that allows unauthenticated users to delete posts on a vulnerable site.
What is the severity of CVE-2021-4359?
The severity of CVE-2021-4359 is medium with a CVSS score of 5.3.
How does CVE-2021-4359 affect the Frontend File Manager plugin?
CVE-2021-4359 affects the Frontend File Manager plugin by allowing unauthenticated users to delete posts without proper authentication and security nonce protection.
Which versions of the Frontend File Manager plugin are affected by CVE-2021-4359?
Versions up to and including 18.2 of the Frontend File Manager plugin are affected by CVE-2021-4359.
Is there a fix available for CVE-2021-4359?
Yes, there is a fix available for CVE-2021-4359. It is recommended to update to a version of the Frontend File Manager plugin that includes the necessary security fixes.