CVE-2022-3125: vulnerability in Frontend File Manager Plugin
Frontend File Manager < 21.3 - Subscriber+ Arbitrary File Upload
Published · Updated
25Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Attendepss 1.5%
from disclosure to weapon
Published on NVDOct 3
VulnCheckSep 7
exploitation probability
1.5%top 27% of all CVEs
observed exploitation
yesVulnCheck
The Frontend File Manager Plugin WordPress plugin before 21.3 allows any authenticated users, such as subscriber, to rename a file to an arbitrary extension, like PHP, which could allow them to basically be able to upload arbitrary files on the server and achieve RCE
Affected products
Unknown · Frontend File Manager PluginRelated CVEs — Frontend File Manager Plugin
In the same product, most dangerous first.
CVE-2022-3124—Frontend File Manager < 21.3 - Unauthenticated File RenamingEPSS 8.3%CVE-2023-5105—Frontend File Manager < 22.6 - Editor+ Arbitrary File DownloadEPSS 1.0%CVE-2026-0829MEDIUMFrontend File Manager Plugin <= 23.5 - Unauthenticated Arbitrary Email SendingEPSS 0.7%CVE-2026-8380MEDIUMFrontend File Manager Plugin <= 23.6 - Author+ Arbitrary Post DeletionEPSS 0.5%CVE-2026-8379HIGHFrontend File Manager Plugin <= 23.6 - Unauthenticated Arbitrary File DownloadEPSS 0.4%CVE-2026-12277HIGHFrontend File Manager Plugin <= 23.6 - Unauthenticated Arbitrary File Deletion via Saved File Metadata Path TraversalEPSS 0.4%