CVE-2021-4369: Frontend File Manager <= 18.2 - Unauthenticated Content Injection
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Content Injection in versions up to, and including, 18.2. This is due to lacking authorization protections, checks against users editing other's posts, and lacking a security nonce, all on the wpfmeditfiletitledesc AJAX action. This makes it possible for unauthenticated attackers to edit the content and title of every page on the site.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-4369?
CVE-2021-4369 is a vulnerability in the Frontend File Manager plugin for WordPress that allows unauthenticated content injection.
What is the severity of CVE-2021-4369?
CVE-2021-4369 has a severity keyword of medium and a severity value of 5.3.
How does CVE-2021-4369 affect the Frontend File Manager plugin for WordPress?
CVE-2021-4369 affects versions up to and including 18.2 of the Frontend File Manager plugin for WordPress.
How can I fix CVE-2021-4369?
To fix CVE-2021-4369, it is recommended to update the Frontend File Manager plugin for WordPress to a version that includes the necessary security fixes.
Where can I find more information about CVE-2021-4369?
For more information about CVE-2021-4369, you can refer to the following references: - [Blog post on nintechnet.com](https://blog.nintechnet.com/wordpress-frontend-file-manager-plugin-fixed-multiple-critical-vulnerabilities/) - [Changeset on plugins.trac.wordpress.org](https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2554359%40nmedia-user-file-uploader&new=2554359%40nmedia-user-file-uploader&sfp_email=&sfph_mail=) - [Wordfence threat intel report](https://www.wordfence.com/threat-intel/vulnerabilities/id/c434e6b8-0dd5-4ffe-93b1-1af614c08f85?source=cve)