VYPR
Medium severity5.8NVD Advisory· Published Feb 17, 2026· Updated Apr 15, 2026

CVE-2026-0829

CVE-2026-0829

Description

The Frontend File Manager Plugin WordPress plugin through 23.5 allows unauthenticated users to send emails through the site without any security checks. This lets attackers use the WordPress site as an open relay for spam or phishing emails to anyone. Attackers can also guess file IDs to access and share uploaded files without permission, exposing sensitive information.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Frontend File Manager Plugin <=23.5 allows unauthenticated email sending (open relay) and file ID guessing, enabling spam and data exposure.

The Frontend File Manager Plugin for WordPress versions through 23.5 contains two critical security flaws. First, it allows unauthenticated users to send emails through the site without any security checks, effectively turning the WordPress installation into an open mail relay. Second, the plugin permits attackers to guess file IDs and access or share uploaded files without proper authorization.

Attackers can exploit the email relay to send spam or phishing emails from the site, bypassing typical email security controls. The file ID guessing attack requires no authentication and can expose sensitive uploaded documents. Both vulnerabilities stem from missing permission checks and predictable file identifiers.

The impact is twofold: the site can be abused for malicious email campaigns, damaging reputation and potentially leading to blacklisting; and confidential files uploaded by legitimate users can be accessed without consent, leading to data leaks.

As of the latest advisory, no fix has been released. Users of the plugin should consider disabling it or implementing additional security measures, such as web application firewalls, to mitigate the risks [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.