PT-2026-52666 · WordPress · Frontend File Manager
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Frontend File Manager Plugin versions prior to 23.7
Description
The plugin fails to properly verify ownership of targeted posts before permanent deletion. This allows authenticated users with author-level access or higher to permanently delete arbitrary posts and pages. Additionally, if an administrator enables the "Allow guest uploads" setting, unauthenticated users can also perform this deletion action.
Recommendations
Update the plugin to a version newer than 23.6.
Disable the "Allow guest uploads" setting to prevent unauthenticated users from exploiting the issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Frontend File Manager