PT-2026-51479 · WordPress · Frontend File Manager Plugin
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Frontend File Manager Plugin versions prior to 23.7
Description
An issue exists where the file download handler does not properly enforce its nonce check. A nonce (number used once) is a security token used to prevent cross-site request forgery. This flaw allows unauthenticated attackers to download files uploaded by any user by iterating identifiers.
Recommendations
Update the plugin to a version newer than 23.6.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Frontend File Manager Plugin