Back to overview

CVE-2026-8379

Description
The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly enforce its nonce check on the file download handler, allowing unauthenticated attackers to download files uploaded by any user through the Frontend File Manager Plugin WordPress plugin through 23.6 by iterating identifiers.

Metadata

CVE ID
CVE-2026-8379
State
PUBLISHED
Assigner
WPScan
Reserved
2026-05-12 08:47 UTC
Published
2026-06-23 06:00 UTC
Last updated
2026-06-23 06:00 UTC
Vendor / Product
Unknown / Frontend File Manager Plugin
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (1)
VendorProductPlatformVersions
Unknown Frontend File Manager Plugin 0 ≤ 23.6
Weakness (CWE)
CWESourceDescription
cna CWE-639 Authorization Bypass Through User-Controlled Key
Back to overview