WordPress Plugin Vulnerabilities

Frontend File Manager < 18.3 - Unauthenticated Content Injection and Stored XSS

Description

The wpfm_edit_file_title_desc AJAX action of the plugin, available to unauthenticated users, did not check if users were editing their own post and was lacking a CSRF nonce as well. This could allow an unauthenticated user to update any post/page. Furthermore, by editing a post with the 'wpfm-files' type, this could also lead to Stored XSS issue as the file_title parameter is not properly sanitised

Affects Plugins

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Jerome Bruandet (nintechnet)
Verified
No

Timeline

Publicly Published
2021-07-12 (about 4 years ago)
Added
2021-07-12 (about 4 years ago)
Last Updated
2023-06-08 (about 2 years ago)

Other