The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulnerable to arbitrary file uploads due to missing file type validation via the `nm_filemanager_upload_file` and `nm_postfront_upload_file` AJAX actions. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
Metrics
Affected Vendors & Products
References
History
Wed, 30 Oct 2024 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Najeebmedia post Front-end Form
|
|
CPEs | cpe:2.3:a:najeebmedia:post_front-end_form:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Najeebmedia post Front-end Form
|
Wed, 16 Oct 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Najeebmedia
Najeebmedia frontend File Manager Najeebmedia n-media Post Front-end Form |
|
CPEs | cpe:2.3:a:najeebmedia:frontend_file_manager:*:*:*:*:*:wordpress:*:* cpe:2.3:a:najeebmedia:n-media_post_front-end_form:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Najeebmedia
Najeebmedia frontend File Manager Najeebmedia n-media Post Front-end Form |
|
Metrics |
ssvc
|
Wed, 16 Oct 2024 07:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulnerable to arbitrary file uploads due to missing file type validation via the `nm_filemanager_upload_file` and `nm_postfront_upload_file` AJAX actions. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible. | |
Title | Frontend File Manager < 4.0 & N-Media Post Front-end Form < 1.1 & - Arbitrary File Upload | |
Weaknesses | CWE-434 | |
References |
|
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-10-16T07:31:49.718Z
Updated: 2024-10-16T17:26:26.917Z
Reserved: 2024-10-15T18:50:11.363Z
Link: CVE-2016-15042
Vulnrichment
Updated: 2024-10-16T17:19:15.923Z
NVD
Status : Analyzed
Published: 2024-10-16T08:15:02.990
Modified: 2024-10-30T21:12:53.463
Link: CVE-2016-15042
Redhat
No data.