CVE-2022-3124: Frontend File Manager < 21.3 - Unauthenticated File Renaming
The Frontend File Manager Plugin WordPress plugin before 21.3 allows any unauthenticated user to rename uploaded files from users. Furthermore, due to the lack of validation in the destination filename, this could allow allow them to change the content of arbitrary files on the web server
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-3124?
CVE-2022-3124 is a vulnerability in the Frontend File Manager Plugin WordPress plugin before version 21.3.
What is the severity of CVE-2022-3124?
CVE-2022-3124 has a severity score of 5.3, which is considered medium.
Who is affected by CVE-2022-3124?
Users of the Frontend File Manager Plugin WordPress plugin version up to and including 21.3 are affected by CVE-2022-3124.
How does CVE-2022-3124 impact users?
CVE-2022-3124 allows any unauthenticated user to rename uploaded files from users and potentially change the content of arbitrary files on the web server.
Is there a fix for CVE-2022-3124?
To fix CVE-2022-3124, users should update to version 21.3 or later of the Frontend File Manager Plugin WordPress plugin.