Vulnerability Details CVE-2022-2356
The Frontend File Manager & Sharing WordPress plugin before 1.1.3 does not filter file extensions when letting users upload files on the server, which may lead to malicious code being uploaded.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 73.9%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2022-2356
-
cpe:2.3:a:mediajedi:user_private_files:1.0.7
-
cpe:2.3:a:mediajedi:user_private_files:1.0.8
-
cpe:2.3:a:mediajedi:user_private_files:1.0.9
-
cpe:2.3:a:mediajedi:user_private_files:1.1.0
-
cpe:2.3:a:mediajedi:user_private_files:1.1.1
-
cpe:2.3:a:mediajedi:user_private_files:1.1.2