Unrated severityNVD Advisory· Published Jul 7, 2026· Updated Jul 7, 2026
Frontend File Manager Plugin <= 23.6 - Unauthenticated Arbitrary File Deletion via Saved File Metadata Path Traversal
CVE-2026-12277
Description
The Frontend File Manager Plugin WordPress plugin through 23.6 does not validate a file path derived from user input before deleting the referenced file, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php) when guest upload mode is enabled. Deleting wp-config.php forces the site into its setup routine, which can be leveraged toward a full site takeover.
Affected products
1- Range: <=23.6
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/30f208f6-9d7b-4aaf-8689-496521d1a1dc/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.