PT-2026-56147 · WordPress · Frontend File Manager Plugin
CVSS v3.1
8.7
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Frontend File Manager Plugin versions prior to 23.7
Description
Insufficient validation of file paths derived from user input allows unauthenticated users to delete arbitrary files on the server when guest upload mode is enabled. This issue can be exploited to delete critical files such as
wp-config.php, which forces the site into its setup routine and can lead to a full site takeover.Recommendations
Update Frontend File Manager Plugin to version 23.7 or later.
Disable guest upload mode as a temporary mitigation measure to prevent unauthenticated file deletion.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Frontend File Manager Plugin