PT-2026-51479 · WordPress · Frontend File Manager Plugin

·

CVE-2026-8379

·

Published

2026-06-23

·

Updated

2026-07-02

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Frontend File Manager Plugin versions prior to 23.7
Description An issue exists where the file download handler does not properly enforce its nonce check. A nonce (number used once) is a security token used to prevent cross-site request forgery. This flaw allows unauthenticated attackers to download files uploaded by any user by iterating identifiers.
Recommendations Update the plugin to a version newer than 23.6.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-8379

Affected Products

Frontend File Manager Plugin