Frontend File Manager Plugin

Frontend File Manager Plugin has 33 disclosed vulnerabilities in the WordSec catalog, reported between 2014 and 2026; 24 are fixed and 9 remain unpatched as of September 2026. Their average CVSS score is 6.9, and the most serious one scores 9.9 out of 10. Severity breakdown: 6 critical and 10 high. 2026 was the busiest year with 10 disclosures.

The most common weakness is Missing Authorization, behind 15 of the records (45%). Other recurring categories include Unrestricted Upload Of File With Dangerous Type, Authorization Bypass Through User-Controlled Key.

24 of the records (73%) have a vendor fix, while 9 remain unpatched. The oldest unresolved one dates back to 2025.

21 independent researchers contributed these findings, most of them (8) reported by Jerome Bruandet.

01234567891025.09.2014Today25.09.20148.8Frontend File Manager Plugin < 3.6 - Arbitrary File Upload CVSS 8.8 · 25.09.201410.06.20159.8Frontend File Manager <= 3.7 - Arbitrary File Upload CVSS 9.8 · 10.06.201516.07.20169.8Frontend File Manager < 4.0 & N-Media Post Front-end Form < 1.1 & - Arbitrary File Upload CVSS 9.8 · 16.07.201612.07.20215.8Frontend File Manager <= 18.2 - Unauthenticated Content Injection CVSS 5.8 · 12.07.20216.4Frontend File Manager <= 18.2 - Privilege Escalation CVSS 6.4 · 12.07.20217.2Frontend File Manager <= 18.2 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 12.07.20219.9Frontend File Manager <= 18.2 - Authenticated Settings Change leading to Arbitrary File Upload CVSS 9.9 · 12.07.20216.5Frontend File Manager Plugin <= 18.2 - Unauthenticated Arbitrary Post Deletion CVSS 6.5 · 12.07.20219.0Frontend File Manager <= 18.2 - Unauthenticated Arbitrary File Download CVSS 9.0 · 12.07.20215.8Frontend File Manager <= 18.2 - Unauthenticated Post Meta Change CVSS 5.8 · 12.07.20217.2Frontend File Manager <= 18.2 - Unauthenticated HTML Injection leading to Spam Emails CVSS 7.2 · 12.07.202106.09.20228.8Frontend File Manager <= 21.3 - Cross-Site Request Forgery to Plugin Settings Update CVSS 8.8 · 06.09.202207.09.20226.5Frontend File Manager <= 21.2 - Missing Authorization CVSS 6.5 · 07.09.20228.8Frontend File Manager <= 21.2 - Authenticated (Subscriber+) Arbitrary File Upload CVSS 8.8 · 07.09.202226.09.20228.8Frontend File Manager Plugin <= 21.2 - Cross-Site Request Forgery to File Upload CVSS 8.8 · 26.09.202213.11.20239.1Frontend File Manager Plugin <= 22.5 - Authenticated (Editor+) Directory Traversal CVSS 9.1 · 13.11.202312.02.20245.3Frontend File Manager <= 22.7 - Sensitive Information Exposure via user uploads CVSS 5.3 · 12.02.202404.07.20254.3Frontend File Manager <= 23.2 - Missing Authorization to Authenticated (Subscriber+) Content Injection CVSS 4.3 · 04.07.202524.07.20257.5Frontend File Manager <= 21.5 - Missing Authorization to Unauthenticated Arbitrary Post Deletion CVSS 7.5 · 24.07.202522.09.20255.3Frontend File Manager <= 23.2 - Missing Authorization CVSS 5.3 · 22.09.202530.10.20254.3Frontend File Manager <= 23.2 - Missing Authorization CVSS 4.3 · 30.10.202524.11.20254.3Frontend File Manager Plugin <= 23.4 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary File Renaming CVSS 4.3 · 24.11.202517.12.20258.1Frontend File Manager <= 23.4 - Authenticated (Subscriber+) Arbitrary File Deletion CVSS 8.1 · 17.12.202516.01.20265.3Frontend File Manager Plugin <= 23.5 - Unauthenticated Insecure Direct Object Reference CVSS 5.3 · 16.01.202627.01.20267.5Frontend File Manager Plugin <= 23.5 - Missing Authorization to Unauthenticated Arbitrary File Sharing via 'file_id' Parameter CVSS 7.5 · 27.01.202617.02.20265.3Frontend File Manager <= 23.5 - Missing Authorization CVSS 5.3 · 17.02.202611.04.20264.3Frontend File Manager <= 23.6 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Download Access CVSS 4.3 · 11.04.202604.06.20264.3Frontend File Manager <= 23.6 - Missing Authorization to Authenticated (Author+) Arbitrary Post Deletion CVSS 4.3 · 04.06.202625.06.20265.3Frontend File Manager Plugin <= 23.6 - Missing Authorization to Unauthenticated File Download CVSS 5.3 · 25.06.20266.4Frontend File Manager Plugin <= 23.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting CVSS 6.4 · 25.06.202627.06.20268.1Frontend File Manager Plugin <= 23.6 - Authenticated (Subscriber+) Arbitrary File Deletion CVSS 8.1 · 27.06.202602.08.20264.3Frontend File Manager Plugin <= 23.6 - Cross-Site Request Forgery CVSS 4.3 · 02.08.202616.08.20269.1Frontend File Manager <= 23.6 - Unauthenticated Arbitrary File Deletion CVSS 9.1 · 16.08.2026

Strategic Overview

Avg CVSSMedium
6.9/ 10
Patch Coverage73%
Open

9

Fixed

24

Get automatic notifications for all Frontend File Manager Plugin vulnerabilities before they are exploited.

Most severe open issueCVSS 9.1CVE-2026-12277

Frontend File Manager <= 23.6 - Unauthenticated Arbitrary File Deletion

Read the full analysis

Vulnerability Records

33 records
2026-08-16 00:00CVE-2026-12277
9.1
Critical
Chamseddine BouzaieneNo
2026-08-02 00:00CVE-2026-16292
4.3
Medium
Yaswanth Reddy SunkaraNo
2026-06-27 11:08CVE-2026-8095
8.1
High
sorawautsukushiiiNo
2026-06-25 00:00CVE-2026-8379
5.3
Medium
Alexander JurkschatNo
2026-06-25 00:00CVE-2026-8378
6.4
Medium
Mohamad Nour AlmujarkeshNo
2026-06-04 00:00CVE-2026-8380
4.3
Medium
Tiago FerreiraNo
2026-04-11 00:00CVE-2026-5337
4.3
Medium
Mohamad Nour AlmujarkeshNo
2026-02-17 00:00CVE-2026-0829
5.3
Medium
ibrahimsqlNo
2026-01-27 21:50CVE-2026-1280
7.5
High
Md. Moniruzzaman Prodhan (NomanProdhan)Yes
2026-01-16 00:00CVE-2026-25005
5.3
Medium
MdrYes
Showing 1–10 of 33 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C