Back to overview

CVE-2026-8380

MEDIUM Exploitation: PoC
6.5
CVSS 3.1
Description
The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly verify ownership of every targeted post before permanent deletion, allowing authenticated users with author-level access and above to permanently delete arbitrary posts and pages. When the Frontend File Manager Plugin WordPress plugin through 23.6's "Allow guest uploads" setting is enabled by an administrator, the same deletion primitive becomes reachable by unauthenticated users.

Metadata

CVE ID
CVE-2026-8380
State
PUBLISHED
Assigner
WPScan
Reserved
2026-05-12 08:47 UTC
Published
2026-06-26 06:00 UTC
Last updated
2026-06-26 15:25 UTC
Vendor / Product
Unknown / Frontend File Manager Plugin
Sources
cve.org  ·  NVD

Severity & Metrics

6.5 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
Unknown Frontend File Manager Plugin 0 ≤ 23.6
Weakness (CWE)
CWESourceDescription
cna CWE-73 External Control of File Name or Path
CVSS scores (1)
ScoreSeverityVersionSourceVector
6.5 MEDIUM 3.1 adp CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Back to overview