PT-2026-99245 · Unknown+1 · File Manager+2

·

CVE-2026-85081

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions File Manager WordPress plugin versions prior to 8.0.5 FileOrganizer WordPress plugin versions prior to 1.2.1 File Manager Pro WordPress plugin versions prior to 2.1.3
Description These plugins fail to correctly validate the origin of window messages received by the file browser loaded on their admin screens. The system accepts any origin that is a leading string prefix of the site's own address. This flaw allows an unauthenticated attacker to execute arbitrary JavaScript within the session of a logged-in administrator who visits a page controlled by the attacker. The issue originates from the bundled file-manager library in versions prior to 2.1.70.
Recommendations Update File Manager WordPress plugin to version 8.0.5 or later. Update FileOrganizer WordPress plugin to version 1.2.1 or later. Update File Manager Pro WordPress plugin to version 2.1.3 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85081

Affected Products

File Manager
File Manager Pro
Fileorganizer