CVE-2022-3125: Frontend File Manager < 21.3 - Subscriber+ Arbitrary File Upload
The Frontend File Manager Plugin WordPress plugin before 21.3 allows any authenticated users, such as subscriber, to rename a file to an arbitrary extension, like PHP, which could allow them to basically be able to upload arbitrary files on the server and achieve RCE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3125?
The severity of CVE-2022-3125 is high with a severity value of 8.8.
How does CVE-2022-3125 impact WordPress websites?
CVE-2022-3125 allows any authenticated user, such as a subscriber, to rename a file to an arbitrary extension, potentially allowing them to upload arbitrary files to achieve remote code execution on the server.
Which version of the Frontend File Manager Plugin is affected by CVE-2022-3125?
The Frontend File Manager Plugin version up to exclusive 21.3 is affected by CVE-2022-3125.
What is CWE-434?
CWE-434 is a vulnerability type that refers to unrestricted upload of file with dangerous type.
Is there a fix available for CVE-2022-3125?
There is no specific fix available for CVE-2022-3125. It is recommended to update to the latest version of the Frontend File Manager Plugin or uninstall the plugin if not needed.