CVE Database · CVE-2022-3126
CVSS v3.1
4.3
EPSS
0.27%
Published
Oct 17, 2022
Modified
May 14, 2025
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
The Frontend File Manager Plugin WordPress plugin before 21.4 does not have CSRF check when uploading files, which could allow attackers to make logged in users upload files on their behalf
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NWeaknesses (CWE)
Affected Products (1)
References (2)