Record summary

CVE-2022-3125 has a selected CVSS score of 8.8 (high).

Description

The Frontend File Manager Plugin WordPress plugin before 21.3 allows any authenticated users, such as subscriber, to rename a file to an arbitrary extension, like PHP, which could allow them to basically be able to upload arbitrary files on the server and achieve RCE

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Sep 7, 2022 · VulnCheck
Reported exploitation
Observed · VulnCheck

Affected products and versions

2
ProductSourceVersion rangeStatus

Frontend File Manager Plugin

CVE List21.3 to < 21.3affected
VulnCheckVersion data not supplied

References

2