Frontend File Manager Plugin, CVE-2022-3125
- CVE, Research URL
- Home page URL
- Application
- Published on
- Oct 03, 2022
- Research Description
- The Frontend File Manager Plugin WordPress plugin before 21.3 allows any authenticated users, such as subscriber, to rename a file to an arbitrary extension, like PHP, which could allow them to basically be able to upload arbitrary files on the server and achieve RCE
- Affected versions
-
Min -, max 21.3.
- Status
-
vulnerable