[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fQqhVTJS1uismwW4O7oeu-6efS_VoCuUBumzeD_9SDGQ":3},{"id":4,"url_slug":5,"title":6,"description":7,"plugin_slug":8,"theme_slug":9,"affected_versions":10,"patched_in_version":11,"severity":12,"cvss_score":13,"cvss_vector":14,"vuln_type":15,"published_date":16,"updated_date":17,"references":18,"days_to_patch":20},"WF-a2c5e232-3561-43a1-bdfa-4a68f20b5889-user-private-files","frontend-file-manager-sharing-user-private-files-missing-authorization","Frontend File Manager & Sharing – User Private Files \u003C= 1.1.1 - Missing Authorization","The Frontend File Manager & Sharing – User Private Files plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.1.1. This is due to missing capability checks and nonce validation on several functions such as dpk_upvf_rmv_file(), dpk_upvf_rmv_access(), and dpk_upvf_update_doc(). This makes it possible for unauthenticated attackers to modify several settings and modify files (via deletion and settings updates).","user-private-files",null,"\u003C=1.1.1","1.1.2","medium",6.3,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:L\u002FI:L\u002FA:L","Missing Authorization","2022-08-06 00:00:00","2024-01-22 19:56:02",[19],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002Fa2c5e232-3561-43a1-bdfa-4a68f20b5889?source=api-prod",535]