CVE-2016-15042
16.10.2024, 08:15
The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulnerable to arbitrary file uploads due to missing file type validation via the `nm_filemanager_upload_file` and `nm_postfront_upload_file` AJAX actions. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.Enginsight
Vendor | Product | Version |
---|---|---|
najeebmedia | frontend_file_manager | 𝑥 < 4.0 |
najeebmedia | n-media_post_front-end_form | 𝑥 ≤ 1.0 |
najeebmedia | frontend_file_manager | 𝑥 < 4.0 |
najeebmedia | post_front-end_form | 𝑥 < 1.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References