PT-2026-36684 · WordPress · Frontend File Manager Plugin

CVE-2026-5337

·

Published

2026-05-03

·

Updated

2026-05-03

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Frontend File Manager Plugin WordPress versions prior to 23.7
Description Authenticated attackers with Subscriber-level access or higher can perform an Insecure Direct Object Reference (IDOR) attack, which occurs when an application provides direct access to objects based on user-supplied input. The issue exists because the plugin fails to properly validate user authorization for requested uploaded files during download requests. By modifying the file id parameter in the 'do=wpfm download' endpoint, an attacker can gain unauthorized read access to sensitive files belonging to other users, including administrators.
Recommendations Update the plugin to a version later than 23.6. As a temporary workaround, restrict access to the 'do=wpfm download' endpoint or the file id parameter to minimize the risk of unauthorized file access.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5337

Affected Products

Frontend File Manager Plugin