PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-14804 WordPress CVE debrief

The Frontend File Manager Plugin WordPress plugin before 23.5 did not validate a path parameter and ownership of the file, allowing any authenticated users, such as subscribers to delete arbitrary files on the server. This CVE was published on 2026-01-07T12:16:56.620Z and was last modified on 2026-09-30T22:10:00.273Z. The NVD entry is currently Deferred.

Vendor
WordPress
Product
Frontend File Manager Plugin
CVSS
HIGH 7.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-07
Original CVE updated
2026-09-30
Advisory published
2026-01-07
Advisory updated
2026-09-30

Who should care

Defenders responsible for WordPress installations with the Frontend File Manager Plugin should assess exposure and prioritize verification and remediation.

Why it matters

CVE-2025-14804 allows authenticated users to delete arbitrary files on the server, potentially leading to data loss and system compromise. Defenders should prioritize verification and remediation.

  • Verify and restrict file deletion access to authorized users
  • Monitor for suspicious file deletion activity
  • Update the Frontend File Manager Plugin to version 23.5 or later

Technical summary

The Frontend File Manager Plugin WordPress plugin before 23.5 did not validate a path parameter and ownership of the file, allowing any authenticated users, such as subscribers to delete arbitrary files on the server. This vulnerability allows attackers to delete files, potentially leading to data loss and system compromise. Defenders should prioritize verifying and updating the Frontend File Manager Plugin to version 23.5 or later, and restrict file deletion access to authorized users.

Defensive priority

Defenders should prioritize verifying and updating the Frontend File Manager Plugin to version 23.5 or later, and restrict file deletion access to authorized users.

Recommended defensive actions

  • Verify and update the Frontend File Manager Plugin to version 23.5 or later
  • Restrict file deletion access to authorized users
  • Monitor for suspicious file deletion activity

Evidence notes

The CVE record and NVD detail page provide information about the vulnerability, but additional verification is needed to confirm affected versions and remediation.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-14804 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-14804

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-14804 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-14804

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.