Vulnerabilities > Najeebmedia > Frontend File Manager > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-10-16 CVE-2016-15042 Unrestricted Upload of File with Dangerous Type vulnerability in Najeebmedia Frontend File Manager and Post Front-End Form
The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulnerable to arbitrary file uploads due to missing file type validation via the `nm_filemanager_upload_file` and `nm_postfront_upload_file` AJAX actions.
network
low complexity
najeebmedia CWE-434
critical
9.8