The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing an attacker to modify the metadata of a logged-in user's uploaded file via a CSRF attack. This can be leveraged to download that file. When guest uploads are enabled, the same action is reachable unauthenticated against any user's file. The plugin's file-met [truncated]
HIGHFrontend File Manager PluginCVE published 2026-07-07
The Frontend File Manager Plugin WordPress plugin through 23.6 has a vulnerability allowing unauthenticated users to delete arbitrary files on the server when guest upload mode is enabled. This can be leveraged toward a full site takeover by deleting critical files such as wp-config.php, which forces the site into its setup routine. The vulnerability is particularly concerning because it can be exploited [truncated]
HIGHFrontend File Manager PluginCVE published 2026-06-23
The CVE-2026-8379 vulnerability affects the Frontend File Manager Plugin for WordPress through version 23.6. This plugin does not properly enforce its nonce check on the file download handler. As a result, unauthenticated attackers can download files uploaded by any user through the Frontend File Manager Plugin WordPress plugin by iterating identifiers. The CVSS score for this vulnerability is 7.5, indica [truncated]