Frontend File Manager Plugin

Explore Frontend File Manager Plugin vulnerabilities across all versions. Currently tracking 30 known vulnerabilities, including severity, impact, and patch status.

01234567891025.09.2014Today25.09.20148.8Frontend File Manager Plugin < 3.6 - Arbitrary File Upload CVSS 8.8 · 25.09.201410.06.20159.8Frontend File Manager <= 3.7 - Arbitrary File Upload CVSS 9.8 · 10.06.201516.07.20169.8Frontend File Manager < 4.0 & N-Media Post Front-end Form < 1.1 & - Arbitrary File Upload CVSS 9.8 · 16.07.201612.07.20219.9Frontend File Manager <= 18.2 - Authenticated Settings Change leading to Arbitrary File Upload CVSS 9.9 · 12.07.20216.4Frontend File Manager <= 18.2 - Privilege Escalation CVSS 6.4 · 12.07.20215.8Frontend File Manager <= 18.2 - Unauthenticated Content Injection CVSS 5.8 · 12.07.20217.2Frontend File Manager <= 18.2 - Unauthenticated HTML Injection leading to Spam Emails CVSS 7.2 · 12.07.20217.2Frontend File Manager <= 18.2 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 12.07.20215.8Frontend File Manager <= 18.2 - Unauthenticated Post Meta Change CVSS 5.8 · 12.07.20216.5Frontend File Manager Plugin <= 18.2 - Unauthenticated Arbitrary Post Deletion CVSS 6.5 · 12.07.20219.0Frontend File Manager <= 18.2 - Unauthenticated Arbitrary File Download CVSS 9.0 · 12.07.202106.09.20228.8Frontend File Manager <= 21.3 - Cross-Site Request Forgery to Plugin Settings Update CVSS 8.8 · 06.09.202207.09.20226.5Frontend File Manager <= 21.2 - Missing Authorization CVSS 6.5 · 07.09.20228.8Frontend File Manager <= 21.2 - Authenticated (Subscriber+) Arbitrary File Upload CVSS 8.8 · 07.09.202226.09.20228.8Frontend File Manager Plugin <= 21.2 - Cross-Site Request Forgery to File Upload CVSS 8.8 · 26.09.202213.11.20239.1Frontend File Manager Plugin <= 22.5 - Authenticated (Editor+) Directory Traversal CVSS 9.1 · 13.11.202312.02.20245.3Frontend File Manager <= 22.7 - Sensitive Information Exposure via user uploads CVSS 5.3 · 12.02.202404.07.20254.3Frontend File Manager <= 23.2 - Missing Authorization to Authenticated (Subscriber+) Content Injection CVSS 4.3 · 04.07.202524.07.20257.5Frontend File Manager <= 21.5 - Missing Authorization to Unauthenticated Arbitrary Post Deletion CVSS 7.5 · 24.07.202522.09.20255.3Frontend File Manager <= 23.2 - Missing Authorization CVSS 5.3 · 22.09.202530.10.20254.3Frontend File Manager <= 23.2 - Missing Authorization CVSS 4.3 · 30.10.202524.11.20254.3Frontend File Manager Plugin <= 23.4 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary File Renaming CVSS 4.3 · 24.11.202517.12.20258.1Frontend File Manager <= 23.4 - Authenticated (Subscriber+) Arbitrary File Deletion CVSS 8.1 · 17.12.202516.01.20265.3Frontend File Manager Plugin <= 23.5 - Unauthenticated Insecure Direct Object Reference CVSS 5.3 · 16.01.202627.01.20267.5Frontend File Manager Plugin <= 23.5 - Missing Authorization to Unauthenticated Arbitrary File Sharing via 'file_id' Parameter CVSS 7.5 · 27.01.202617.02.20265.3Frontend File Manager <= 23.5 - Missing Authorization CVSS 5.3 · 17.02.202611.04.20264.3Frontend File Manager <= 23.6 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Download Access CVSS 4.3 · 11.04.202625.06.20265.3Frontend File Manager Plugin <= 23.6 - Missing Authorization to Unauthenticated File Download CVSS 5.3 · 25.06.20266.4Frontend File Manager Plugin <= 23.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting CVSS 6.4 · 25.06.202627.06.20268.1Frontend File Manager Plugin <= 23.6 - Authenticated (Subscriber+) Arbitrary File Deletion CVSS 8.1 · 27.06.2026

Strategic Overview

Avg CVSSMedium
7.0/ 10
Patch Coverage80%
Open

6

Fixed

24

Get automatic notifications for all Frontend File Manager Plugin vulnerabilities before they are exploited.

Vulnerability Records

30 records
2026-06-27 11:08CVE-2026-8095
8.1
High
sorawautsukushiiiNo
2026-06-25 00:00CVE-2026-8379
5.3
Medium
Alexander JurkschatNo
2026-06-25 00:00CVE-2026-8378
6.4
Medium
Mohamad Nour AlmujarkeshNo
2026-04-11 00:00CVE-2026-5337
4.3
Medium
Mohamad Nour AlmujarkeshNo
2026-02-17 00:00CVE-2026-0829
5.3
Medium
ibrahimsqlNo
2026-01-27 21:50CVE-2026-1280
7.5
High
Md. Moniruzzaman Prodhan (NomanProdhan)Yes
2026-01-16 00:00CVE-2026-25005
5.3
Medium
MdrYes
2025-12-17 00:00CVE-2025-14804
8.1
High
Gregory AllegoetYes
2025-11-24 19:15CVE-2025-13382
4.3
Medium
t.t.brothersYes
2025-10-30 00:00CVE-2025-64265
4.3
Medium
Legion HunterYes
Showing 1–10 of 30 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C