Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total6
Critical0
High2
Medium4
Reset
Showing 1-6 of 6 records
Threat Entry Updated 2026-07-07

CVE-2026-12277 - Through 23 Plugin

The Frontend File Manager Plugin WordPress plugin through 23.6 does not validate a file path derived from user input before deleting the referenced file, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php) when guest upload mode is enabled. Deleting wp-config.php forces the site into its setup routine, which can be leveraged toward a full site takeover.

PLUGIN Through 23

CVE-2026-12277

HIGH CVSS 8.7 2026-07-07
Threat Entry Updated 2026-06-26

CVE-2026-8380 - Through 23 Plugin

The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly verify ownership of every targeted post before permanent deletion, allowing authenticated users with author-level access and above to permanently delete arbitrary posts and pages. When the Frontend File Manager Plugin WordPress plugin through 23.6's "Allow guest uploads" setting is enabled by an administrator, the same deletion primitive becomes reachable by unauthenticated users.

PLUGIN Through 23

CVE-2026-8380

MEDIUM CVSS 6.5 2026-06-26
Threat Entry Updated 2026-06-23

CVE-2026-8379 - Through 23 Plugin

The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly enforce its nonce check on the file download handler, allowing unauthenticated attackers to download files uploaded by any user through the Frontend File Manager Plugin WordPress plugin through 23.6 by iterating identifiers.

PLUGIN Through 23

CVE-2026-8379

HIGH CVSS 7.5 2026-06-23
Threat Entry Updated 2026-06-23

CVE-2026-8378 - Through 23 Plugin

The Frontend File Manager Plugin WordPress plugin through 23.6 does not sanitise nor escape a filename submitted to the frontend file-rename endpoint before storing it as post meta and rendering it back on the admin File Manager listing, leading to a Stored Cross-Site Scripting vulnerability exploitable by users with Subscriber-level access and above against an administrator viewing the file management interface.

PLUGIN Through 23

CVE-2026-8378

MEDIUM CVSS 5.4 2026-06-23
Threat Entry Updated 2026-06-17

CVE-2026-5337 - Through 23 Plugin

During the analysis, it was identified that authenticated attackers with Subscriber-level access or higher are able to perform an Insecure Direct Object Reference (IDOR) attack. This vulnerability exists because the Frontend File Manager Plugin WordPress plugin through 23.6 does not properly validate user authorization for the requested uploaded file when processing download requests. By modifying the value of the 'file_id' parameter in the download endpoint (e.g., http://localhost/?do=wpfm_download&file_id=40&nm_file_nonce=a36fb893f1), an attacker can access files belonging to other users, including privileged users such as administrators. This allows unauthorized access/read to sensitive data stored…

PLUGIN Through 23

CVE-2026-5337

MEDIUM CVSS 6.5 2026-05-03
Threat Entry Updated 2026-06-17

CVE-2026-0829 - Through 23 Plugin

The Frontend File Manager Plugin WordPress plugin through 23.5 allows unauthenticated users to send emails through the site without any security checks. This lets attackers use the WordPress site as an open relay for spam or phishing emails to anyone. Attackers can also guess file IDs to access and share uploaded files without permission, exposing sensitive information.

PLUGIN Through 23

CVE-2026-0829

MEDIUM CVSS 5.8 2026-02-17
Scroll to top