CVE-2023-5105: fallo en Frontend File Manager Plugin
Frontend File Manager < 22.6 - Editor+ Arbitrary File Download
Publicada el · Actualizada el
3Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackepss 1.0%
probabilidad de explotación
1.0%top 37% de las CVE
explotación observada
noninguna fuente lo reporta
The Frontend File Manager Plugin WordPress plugin before 22.6 has a vulnerability that allows an Editor+ user to bypass the file download logic and download files such as `wp-config.php`
Productos afectados
Unknown · Frontend File Manager PluginCVEs relacionadas — Frontend File Manager Plugin
En el mismo producto, de las más peligrosas a las menos.
CVE-2022-3124—Frontend File Manager < 21.3 - Unauthenticated File RenamingEPSS 8.3%CVE-2022-3125—Frontend File Manager < 21.3 - Subscriber+ Arbitrary File UploadEPSS 1.5%CVE-2026-0829MEDIUMFrontend File Manager Plugin <= 23.5 - Unauthenticated Arbitrary Email SendingEPSS 0.7%CVE-2026-8380MEDIUMFrontend File Manager Plugin <= 23.6 - Author+ Arbitrary Post DeletionEPSS 0.5%CVE-2026-8379HIGHFrontend File Manager Plugin <= 23.6 - Unauthenticated Arbitrary File DownloadEPSS 0.4%CVE-2026-12277HIGHFrontend File Manager Plugin <= 23.6 - Unauthenticated Arbitrary File Deletion via Saved File Metadata Path TraversalEPSS 0.4%