The Frontend File Manager plugin (<4.0) and N-Media Post Front-end Form plugin (<1.1) for WordPress were vulnerable to arbitrary file uploads due to missing file type validation. This allowed unauthenticated attackers to upload arbitrary files and potentially achieve remote code execution.
id: CVE-2016-15042
info:
name: WordPress Frontend File Manager < 4.0 & N-Media Post Frontend < 1.
...