
🚨 CVE-2021-4356: Frontend File Manager <= 18.2 - U... WordPress wp-config.php, database dumps, and private keys are three AJAX calls away from any script kiddie with curl. #W... https://zerodaysignal.com/vulnerability/CVE-2021-4356 #netsec #vulnerability #CVE #sysadmin #zeroday
Post summary
The post announces CVE-2021-4356, noting that sensitive WordPress files are trivially accessible via AJAX calls in the Frontend File Manager, and links to a vulnerability page for more details.
