PatchSiren cyber security CVE debrief
CVE-2025-14804 WordPress CVE debrief
The Frontend File Manager Plugin WordPress plugin before 23.5 did not validate a path parameter and ownership of the file, allowing any authenticated users, such as subscribers to delete arbitrary files on the server. This CVE was published on 2026-01-07T12:16:56.620Z and was last modified on 2026-09-30T22:10:00.273Z. The NVD entry is currently Deferred.
- Vendor
- WordPress
- Product
- Frontend File Manager Plugin
- CVSS
- HIGH 7.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-07
- Original CVE updated
- 2026-09-30
- Advisory published
- 2026-01-07
- Advisory updated
- 2026-09-30
Who should care
Defenders responsible for WordPress installations with the Frontend File Manager Plugin should assess exposure and prioritize verification and remediation.
Why it matters
CVE-2025-14804 allows authenticated users to delete arbitrary files on the server, potentially leading to data loss and system compromise. Defenders should prioritize verification and remediation.
- Verify and restrict file deletion access to authorized users
- Monitor for suspicious file deletion activity
- Update the Frontend File Manager Plugin to version 23.5 or later
Technical summary
The Frontend File Manager Plugin WordPress plugin before 23.5 did not validate a path parameter and ownership of the file, allowing any authenticated users, such as subscribers to delete arbitrary files on the server. This vulnerability allows attackers to delete files, potentially leading to data loss and system compromise. Defenders should prioritize verifying and updating the Frontend File Manager Plugin to version 23.5 or later, and restrict file deletion access to authorized users.
Defensive priority
Defenders should prioritize verifying and updating the Frontend File Manager Plugin to version 23.5 or later, and restrict file deletion access to authorized users.
Recommended defensive actions
- Verify and update the Frontend File Manager Plugin to version 23.5 or later
- Restrict file deletion access to authorized users
- Monitor for suspicious file deletion activity
Evidence notes
The CVE record and NVD detail page provide information about the vulnerability, but additional verification is needed to confirm affected versions and remediation.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-14804 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-14804
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-14804 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-14804
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/c572c0ad-1b36-49ce-b254-2181e53abb46/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.