First published: Mon Dec 04 2023(Updated: )
The Frontend File Manager Plugin WordPress plugin before 22.6 has a vulnerability that allows an Editor+ user to bypass the file download logic and download files such as `wp-config.php`
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
N-Media Frontend File Manager | <22.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-5105.
The title of this vulnerability is 'Frontend File Manager < 22.6 - Editor+ Arbitrary File Download'.
The severity of CVE-2023-5105 is medium with a severity value of 6.5.
CVE-2023-5105 affects the Frontend File Manager Plugin WordPress plugin before version 22.6.
The CWE of CVE-2023-5105 is CWE-200 and CWE-22.