PT-2026-56147 · WordPress · Frontend File Manager Plugin

·

CVE-2026-12277

·

Published

2026-07-07

·

Updated

2026-07-07

CVSS v3.1

8.7

High

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Frontend File Manager Plugin versions prior to 23.7
Description Insufficient validation of file paths derived from user input allows unauthenticated users to delete arbitrary files on the server when guest upload mode is enabled. This issue can be exploited to delete critical files such as wp-config.php, which forces the site into its setup routine and can lead to a full site takeover.
Recommendations Update Frontend File Manager Plugin to version 23.7 or later. Disable guest upload mode as a temporary mitigation measure to prevent unauthenticated file deletion.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-12277

Affected Products

Frontend File Manager Plugin