Najeebmedia
najeebmedia
26 CVEs • 12 products
Products (12)
Click to collapseToggle
Products (12)
Click to collapse
CVEs (26)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Najeebmedia 1Website Contact Form With File Upload Dec 16, 2025 Jul 22, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The Website Contact Form With File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_file()' function in versions up to, and including, 1.3.4. This mak...Show more |
1Najeebmedia 1Simple User Registration Apr 8, 2026 Jun 26, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3. This is due to insufficient restrictions on user meta values that can be supplied during...Show more |
The Easy Quiz Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wqt-question' shortcode in all versions up to, and including, 2.0 due to insufficient input sanitization and output...Show more |
1Najeebmedia 1Simple User Registration Apr 23, 2026 Oct 20, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Authentication Bypass Using an Alternate Path or Channel vulnerability in N-Media Simple User Registration wp-registration allows Authentication Bypass.This issue affects Simple User Registration: from n/a through <= 6.7...Show more |
1Najeebmedia 2Frontend File Manager Post Front End FormOct 30, 2024 Oct 16, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulnerable to arbitrary file uploads due to missing file type validation via the `nm_filemanager_upload_f...Show more |
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in N-Media Frontend File Manager.This issue affects Frontend File Manager: from n/a through 22.7. |
The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0. This is due to missing or incorrect nonce validation on several...Show more |
The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.0. This is due to missing or incorrect capability checks on several aja...Show more |
1Najeebmedia 1Frontend File Manager Plugin Nov 21, 2024 Dec 4, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The Frontend File Manager Plugin WordPress plugin before 22.6 has a vulnerability that allows an Editor+ user to bypass the file download logic and download files such as `wp-config.php` |
1Najeebmedia 1Frontend File Manager Plugin Apr 8, 2026 Jun 7, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Content Injection in versions up to, and including, 18.2. This is due to lacking authorization protections, checks against users editing oth...Show more |
1Najeebmedia 1Frontend File Manager Plugin Apr 8, 2026 Jun 7, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The Frontend File Manager plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 18.2. This is due to lacking capability checks and a security nonce, all on the wpfm_save_se...Show more |
1Najeebmedia 1Frontend File Manager Plugin Apr 8, 2026 Jun 7, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to, and including, 18.2. This is due to lacking authentication protections and santisation all on...Show more |
1Najeebmedia 1Frontend File Manager Plugin Apr 8, 2026 Jun 7, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and including, 18.2. This is due to lacking authentication protections and lacking a security non...Show more |
1Najeebmedia 1Frontend File Manager Plugin Apr 8, 2026 Jun 7, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Download in versions up to, and including, 18.2. This is due to lacking authentication protections, capability checks, and...Show more |
1Najeebmedia 1Frontend File Manager Plugin Apr 8, 2026 Jun 7, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Post Meta Change in versions up to, and including, 18.2. This is due to lacking authentication protections, capability checks, and sanitizat...Show more |
1Najeebmedia 1Frontend File Manager Plugin Apr 8, 2026 Jun 7, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated HTML Injection in versions up to, and including, 18.2. This is due to lacking authentication protections on the wpfm_send_file_in_email AJAX...Show more |
1Najeebmedia 1Frontend File Manager Plugin Apr 8, 2026 Jun 7, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Frontend File Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 18.2. This is due to lacking mishandling the use of user IDs that is accessible by the visitor. This...Show more |
1Najeebmedia 1Woocommerce Checkout Field Manager Mar 4, 2025 Mar 6, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The WooCommerce Checkout Field Manager WordPress plugin before 18.0 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as PHP on the server |
1Najeebmedia 1Frontend File Manager Plugin May 14, 2025 Oct 17, 2022 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The Frontend File Manager Plugin WordPress plugin before 21.4 does not have CSRF check when uploading files, which could allow attackers to make logged in users upload files on their behalf |
The Frontend File Manager Plugin WordPress plugin before 21.3 allows any authenticated users, such as subscriber, to rename a file to an arbitrary extension, like PHP, which could allow them to basically be able to uploa...Show more |