WordPress File Management Plugin Riddled with Critical Bugs
#1
Information 
Quote:A critical cross-site scripting (XSS) bug impacts WordPress sites running the Frontend File Manager plugin and allows remote unauthenticated users to inject JavaScript code into vulnerable websites to create admin user accounts.
 
The bug is one of six critical flaws impacting the WordPress plugin Front File Manager versions 17.1 and 18.2, active on more than 2,000 websites. Each of the flaws, publicly disclosed Monday, have available patches.
 
The bugs open sites running the plugin to a broad range of remote code execution attacks giving adversaries the ability to change or delete posts, set up a spam relay, achieve privilege escalation, carry out stored cross-site scripting (XSS) attacks, according to researchers from the Ninja Technologies Network.
 
The WordPress plugin is designed to allow users to upload files to a website admin. Each file is saved in a private directory, so each user can manage their own files after login.

Read more: WordPress File Management Plugin Riddled with Critical Bugs | Threatpost
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Messages In This Thread
WordPress File Management Plugin Riddled with Critical Bugs - by silversurfer - 13 July 21, 12:54

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Microsoft Edge 145.0.3800.58
Version 145.0.3800...harlan4096 — 09:28
AnyDesk 9.6.11 for Windows / 9.6.3 for m...
AnyDesk 9.6.11 for...harlan4096 — 09:03
Google Chrome 145.0.7632.75/76
Google Chrome 145....harlan4096 — 08:59
Vivaldi 7.8 Build 3925.66
Vivaldi 7.8 Build ...harlan4096 — 08:58
New Windows 11 Update Adds Built-In Sysm...
Microsoft is rolli...harlan4096 — 10:11

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (38)showercurtains
avatar (49)PeterWhink
avatar (46)dimaWeami
avatar (39)TranoTymn
avatar (39)MezirLal
avatar (38)Michaelaburi
avatar (46)dpascoal
avatar (51)Ronaldduh
avatar (39)legalgauch
avatar (44)Baihu
avatar (27)RaseinsLikes

[-]
Online Staff
There are no staff members currently online.

>