← Back to browse · API

CVE-2016-15042

Severity
CRITICAL
CVSS
9.8
EPSS
0.05672
Risk score
41.19
CISA KEV
No
PoC
No
Published
2024-10-16
Modified
2026-04-08
First seen
2026-08-07
Aliases
EUVD-2016-10786, GHSA-98V8-MH4J-WQG7
Products
Unknown:Frontend File Manager Plugin 0 <4.0, nmedia:N-Media Post Front-end Form 0 ≤1.0
Sources
euvd EUVD-2016-10786

Description

The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulnerable to arbitrary file uploads due to missing file type validation via the `nm_filemanager_upload_file` and `nm_postfront_upload_file` AJAX actions. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

References