PatchSiren

Frontend File Manager Plugin CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Frontend File Manager Plugin CVE published 2026-08-02

CVE-2026-16292

The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing an attacker to modify the metadata of a logged-in user's uploaded file via a CSRF attack. This can be leveraged to download that file. When guest uploads are enabled, the same action is reachable unauthenticated against any user's file. The plugin's file-met [truncated]

HIGH Frontend File Manager Plugin CVE published 2026-07-07

CVE-2026-12277

The Frontend File Manager Plugin WordPress plugin through 23.6 has a vulnerability allowing unauthenticated users to delete arbitrary files on the server when guest upload mode is enabled. This can be leveraged toward a full site takeover by deleting critical files such as wp-config.php, which forces the site into its setup routine. The vulnerability is particularly concerning because it can be exploited [truncated]

HIGH Frontend File Manager Plugin CVE published 2026-06-23

CVE-2026-8379

The CVE-2026-8379 vulnerability affects the Frontend File Manager Plugin for WordPress through version 23.6. This plugin does not properly enforce its nonce check on the file download handler. As a result, unauthenticated attackers can download files uploaded by any user through the Frontend File Manager Plugin WordPress plugin by iterating identifiers. The CVSS score for this vulnerability is 7.5, indica [truncated]