Access violation vulnerability in Frontend File Manager Plugin 18.3

The Frontend File Manager plugin for WordPress is a program that allows users to manage their WordPress files. Unfortunately, a security vulnerability has been discovered in versions up to and including 18.2. This vulnerability allows unauthenticated attackers to edit the content and title of every page on the website, as the plugin does not have sufficient security protections to prevent this. Additionally, there are no checks to stop users from editing other people’s posts, and there is no security nonce on the wpfm_edit_file_title_desc AJAX action.

Detected in:

Frontend File Manager Plugin open vulnerable versions: >= * < 18.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.