Lucene search

K
cvelistWPScanCVELIST:CVE-2022-3126
HistoryOct 17, 2022 - 12:00 a.m.

CVE-2022-3126 Frontend File Manager < 21.4 - File Upload via CSRF

2022-10-1700:00:00
CWE-352
WPScan
www.cve.org
3
frontend file manager
csrf
file upload
wordpress
plugin security

AI Score

5

Confidence

High

EPSS

0.001

Percentile

25.9%

The Frontend File Manager Plugin WordPress plugin before 21.4 does not have CSRF check when uploading files, which could allow attackers to make logged in users upload files on their behalf

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "Frontend File Manager Plugin",
    "versions": [
      {
        "version": "21.4",
        "status": "affected",
        "lessThan": "21.4",
        "versionType": "custom"
      }
    ]
  }
]

AI Score

5

Confidence

High

EPSS

0.001

Percentile

25.9%

Related for CVELIST:CVE-2022-3126