CVE detail
CVE-2023-4930 — CVE-2023-4930
Published 2023-11-06 · Modified 2026-06-17 · Vendor shamimsplugins · Product front_end_pm · Source nvd
MEDIUM
severity
CVSS-derived band
0.0041
EPSS probability
exploitation probability, 30d
34.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The Front End PM WordPress plugin before 11.4.3 does not block listing the contents of the directories where it stores attachments to private messages, allowing unauthenticated visitors to list and download private attachments if the autoindex feature of the web server is enabled.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References