VYPR

Nmedia User File Uploader

by WordPress

Source repositories

CVEs (4)

  • CVE-2026-1280HigJan 28, 2026
    risk 0.49cvss 7.5epss 0.00

    The Frontend File Manager Plugin for WordPress is vulnerable to unauthorized file sharing due to a missing capability check on the 'wpfm_send_file_in_email' AJAX action in all versions up to, and including, 23.5. This makes it possible for unauthenticated attackers to share…

  • CVE-2023-7306HigJul 25, 2025
    risk 0.42cvss 7.5epss 0.00

    The Frontend File Manager Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wpfm_delete_multiple_files() function in all versions up to, and including, 21.5. This makes it possible for unauthenticated attackers to…

  • CVE-2025-64265MedNov 13, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Frontend File Manager: from n/a through <= 23.2.

  • CVE-2026-8095HigJun 28, 2026
    risk 0.00cvss 8.1epss 0.00

    The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions up to and including 23.6. This is due to a case-sensitive bypass of the wpfm_dir_path parameter sanitization in the wpfm_file_meta_update AJAX handler, where…