VYPR

Frontend File Manager Plugin

by WordPress

CVEs (17)

  • CVE-2022-3125HigOct 3, 2022
    risk 0.57cvss 8.8epss 0.01

    The Frontend File Manager Plugin WordPress plugin before 21.3 allows any authenticated users, such as subscriber, to rename a file to an arbitrary extension, like PHP, which could allow them to basically be able to upload arbitrary files on the server and achieve RCE

  • CVE-2022-2356HigAug 8, 2022
    risk 0.57cvss 8.8epss 0.01

    The Frontend File Manager & Sharing WordPress plugin before 1.1.3 does not filter file extensions when letting users upload files on the server, which may lead to malicious code being uploaded.

  • CVE-2025-14804HigJan 7, 2026
    risk 0.50cvss 7.7epss 0.00

    The Frontend File Manager Plugin WordPress plugin before 23.5 did not validate a path parameter and ownership of the file, allowing any authenticated users, such as subscribers to delete arbitrary files on the server

  • CVE-2026-8379HigJun 23, 2026
    risk 0.49cvss 7.5epss 0.00

    The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly enforce its nonce check on the file download handler, allowing unauthenticated attackers to download files uploaded by any user through the Frontend File Manager Plugin WordPress plugin through 23.6…

  • CVE-2026-1280HigJan 28, 2026
    risk 0.49cvss 7.5epss 0.00

    The Frontend File Manager Plugin for WordPress is vulnerable to unauthorized file sharing due to a missing capability check on the 'wpfm_send_file_in_email' AJAX action in all versions up to, and including, 23.5. This makes it possible for unauthenticated attackers to share…

  • CVE-2026-5337MedMay 3, 2026
    risk 0.42cvss 6.5epss 0.00

    During the analysis, it was identified that authenticated attackers with Subscriber-level access or higher are able to perform an Insecure Direct Object Reference (IDOR) attack. This vulnerability exists because the Frontend File Manager Plugin WordPress plugin through 23.6 does…

  • CVE-2023-7306HigJul 25, 2025
    risk 0.42cvss 7.5epss 0.00

    The Frontend File Manager Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wpfm_delete_multiple_files() function in all versions up to, and including, 21.5. This makes it possible for unauthenticated attackers to…

  • CVE-2023-5105MedDec 4, 2023
    risk 0.42cvss 6.5epss 0.01

    The Frontend File Manager Plugin WordPress plugin before 22.6 has a vulnerability that allows an Editor+ user to bypass the file download logic and download files such as `wp-config.php`

  • CVE-2026-0829MedFeb 17, 2026
    risk 0.38cvss 5.8epss 0.01

    The Frontend File Manager Plugin WordPress plugin through 23.5 allows unauthenticated users to send emails through the site without any security checks. This lets attackers use the WordPress site as an open relay for spam or phishing emails to anyone. Attackers can also guess…

  • CVE-2026-8378MedJun 23, 2026
    risk 0.35cvss 5.4epss 0.00

    The Frontend File Manager Plugin WordPress plugin through 23.6 does not sanitise nor escape a filename submitted to the frontend file-rename endpoint before storing it as post meta and rendering it back on the admin File Manager listing, leading to a Stored Cross-Site Scripting…

  • CVE-2022-3124MedOct 3, 2022
    risk 0.35cvss 5.3epss 0.07

    The Frontend File Manager Plugin WordPress plugin before 21.3 allows any unauthenticated user to rename uploaded files from users. Furthermore, due to the lack of validation in the destination filename, this could allow allow them to change the content of arbitrary files on the…

  • CVE-2025-13382MedNov 25, 2025
    risk 0.28cvss 4.3epss 0.00

    The Frontend File Manager Plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 23.4. This is due to the plugin not validating file ownership before processing file rename requests in the '/wpfm/v1/file-rename' REST API…

  • CVE-2022-3126MedOct 17, 2022
    risk 0.28cvss 4.3epss 0.00

    The Frontend File Manager Plugin WordPress plugin before 21.4 does not have CSRF check when uploading files, which could allow attackers to make logged in users upload files on their behalf

  • CVE-2026-16292MedAug 2, 2026
    risk 0.00cvss 5.4epss 0.00

    The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing an attacker to modify the metadata of a logged-in user's uploaded file via a CSRF attack, which can be leveraged to download that…

  • CVE-2026-12277HigJul 7, 2026
    risk 0.00cvss 8.7epss 0.00

    The Frontend File Manager Plugin WordPress plugin through 23.6 does not validate a file path derived from user input before deleting the referenced file, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php) when guest upload mode is…

  • CVE-2026-8095HigJun 28, 2026
    risk 0.00cvss 8.1epss 0.00

    The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions up to and including 23.6. This is due to a case-sensitive bypass of the wpfm_dir_path parameter sanitization in the wpfm_file_meta_update AJAX handler, where…

  • CVE-2026-8380MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly verify ownership of every targeted post before permanent deletion, allowing authenticated users with author-level access and above to permanently delete arbitrary posts and pages. When the Frontend…