PT-2026-52666 · WordPress · Frontend File Manager

·

CVE-2026-8380

·

Published

2026-06-26

·

Updated

2026-06-26

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Frontend File Manager Plugin versions prior to 23.7
Description The plugin fails to properly verify ownership of targeted posts before permanent deletion. This allows authenticated users with author-level access or higher to permanently delete arbitrary posts and pages. Additionally, if an administrator enables the "Allow guest uploads" setting, unauthenticated users can also perform this deletion action.
Recommendations Update the plugin to a version newer than 23.6. Disable the "Allow guest uploads" setting to prevent unauthenticated users from exploiting the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-8380

Affected Products

Frontend File Manager