← Back to browse · API

CVE-2021-4368

Severity
CRITICAL
CVSS
9.9
EPSS
0.01853
Risk score
40.25
CISA KEV
No
PoC
No
Published
2023-06-07
Modified
2026-04-08
First seen
2026-08-07
Aliases
EUVD-2021-34195, GHSA-254W-GR7H-WVH4
Products
Unknown:Frontend File Manager Plugin 0 <18.3
Sources
euvd EUVD-2021-34195

Description

The Frontend File Manager plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 18.2. This is due to lacking capability checks and a security nonce, all on the wpfm_save_settings AJAX action. This makes it possible for subscriber-level attackers to edit the plugin settings, such as the allowed upload file types. This can lead to remote code execution through other vulnerabilities.

References