Frontend File Manager < 4.0 & N-Media Post Front-end Form < 1.1 & - Arbitrary File Upload
Published Oct 16, 2024
9.8
CRITICALCVSS 3.1
EPSS 5.72%
Description
The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulnerable to arbitrary file uploads due to missing file type validation via the `nm_filemanager_upload_file` and `nm_postfront_upload_file` AJAX actions. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
Affected products
-
- Version 0StatusaffectedConstraints<4.0
- Version
-
- Version 0StatusaffectedConstraints<=1.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Nmedia | Frontend File Manager Plugin | unaffected |
| ||||||
| Nmedia | N-Media Post Front-end Form | unaffected |
|
- < 4.0
- < 1.1
-
- Version 0StatusaffectedConstraints<4.0
- Version
-
- Version 0StatusaffectedConstraints<=1.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Najeebmedia | Frontend File Manager | n/a |
| ||||||
| Najeebmedia | N-Media Post Front-End Form | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Oct 16, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (21 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 5.72% (0.05719) | 92.80th | v5 (v2026.06.15) |
| Jun 15, 2026 | 5.56% (0.05561) | 91.83th | v5 (v2026.06.15) |
| Apr 30, 2026 | 75.83% (0.75827) | 98.92th | v4 (v2025.03.14) |
| Mar 7, 2026 | 73.85% (0.73854) | 98.80th | v4 (v2025.03.14) |
| Feb 8, 2026 | 69.40% (0.69401) | 98.61th | v4 (v2025.03.14) |
| Feb 5, 2026 | 67.64% (0.67636) | 98.53th | v4 (v2025.03.14) |
| Jan 30, 2026 | 72.19% (0.72186) | 98.71th | v4 (v2025.03.14) |
| Dec 8, 2025 | 70.79% (0.70789) | 98.63th | v4 (v2025.03.14) |
| Sep 19, 2025 | 72.80% (0.72798) | 98.74th | v4 (v2025.03.14) |
| Sep 16, 2025 | 71.79% (0.71794) | 98.69th | v4 (v2025.03.14) |
| Sep 10, 2025 | 51.37% (0.51368) | 97.81th | v4 (v2025.03.14) |
| Jul 2, 2025 | 7.47% (0.07471) | 91.35th | v4 (v2025.03.14) |
| May 22, 2025 | 6.24% (0.06239) | 90.38th | v4 (v2025.03.14) |
| Mar 30, 2025 | 4.42% (0.04422) | 87.97th | v4 (v2025.03.14) |
| Mar 29, 2025 | 39.61% (0.39607) | 95.94th | v4 (v2025.03.14) |
| Mar 26, 2025 | 4.42% (0.04422) | 87.89th | v4 (v2025.03.14) |
| Mar 24, 2025 | 3.18% (0.03180) | 85.78th | v4 (v2025.03.14) |
| Mar 23, 2025 | 12.35% (0.12350) | 92.90th | v4 (v2025.03.14) |
| Mar 17, 2025 | 2.83% (0.02829) | 85.25th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.10% (0.00102) | 43.30th | v3 (v2023.03.01) |
| Oct 17, 2024 | 0.10% (0.00099) | 41.96th | v3 (v2023.03.01) |
References (6)
- https://wordpress.org/plugins/nmedia-user-file-uploader/#developers Product
- https://wpscan.com/vulnerability/052f7d9a-aaff-4fb1-92b7-aeb83cc705a7 Third Party Advisory
- https://www.acunetix.com/vulnerabilities/web/wordpress-plugin-n-media-post-front-end-form-arbitrary-file-upload-1-0/ Third Party Advisory
- https://www.pluginvulnerabilities.com/2016/09/19/arbitrary-file-upload-vulnerability-in-front-end-file-upload-and-manager-plugin/ ExploitThird Party Advisory
- https://www.pluginvulnerabilities.com/2016/09/19/arbitrary-file-upload-vulnerability-in-n-media-post-front-end-form/ ExploitThird Party Advisory
- https://www.wordfence.com/threat-intel/vulnerabilities/id/2c1e6298-f243-49a5-b1b7-52bd6a6c8858?source=cve Third Party Advisory
Change history (0)
No recorded changes yet.