WP Media File Type Manager

WP Media File Type Manager has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).

The one issue recorded for WP Media File Type Manager has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.

All of these findings were reported by 0xd4rk5id3. WP Media File Type Manager is installed on roughly 200 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage0%
Open

1

Fixed

0

Get automatic notifications for all WP Media File Type Manager vulnerabilities before they are exploited.

Most severe open issueCVSS 4.3CVE-2025-27359

WP Media File Type Manager <= 2.3.0 - Cross-Site Request Forgery to Settings Update

Read the full analysis

Vulnerability Records

1 records
Plugin Profile
Latestv2.3.3

WP Media File Type Manager

Seerox

Author

Seerox

0.0(0)
0/100
Last Updated
2026-06-30 (3mo ago)
Active Installs
200+
Downloads
11,451
Requires WP
3.8+
Requires PHP
0+
Tested up to
WP 7.0.4
Created
2017-09-02 (9y ago)

Seerox brings another exciting plugin for you. This plugin will allow you to manage different file types in Media Library, So if you want to Enable/Disable any specific file type in media library to upload for Security reasons. Using this plugin you can control permissions for Your Site users to upload specific type of files not only from media library section but also from frontend. Features Adds file extensions that WordPress doesn’t support by default

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C