« Back to list

Najeebmedia

Najeebmedia Frontend File Manager: vulnerabilities and CVEs

Najeebmedia Frontend File Manager has 16 published vulnerabilities, 11 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs16
Last 12 months11
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-16292Medium (5.4)0.13%—Aug 2, 2026
The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing an attacker to modify the metadata of a logged-in user's uploaded…
CVE-2026-12277High (8.7)0.39%—Jul 7, 2026
The Frontend File Manager Plugin WordPress plugin through 23.6 does not validate a file path derived from user input before deleting the referenced file, allowing unauthenticated users to delete arbitrary files on the…
CVE-2026-8095High (8.1)0.60%—Jun 28, 2026
The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions up to and including 23.6. This is due to a case-sensitive bypass of the wpfm_dir_path parameter…
CVE-2026-8380Medium (6.5)0.47%—Jun 26, 2026
The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly verify ownership of every targeted post before permanent deletion, allowing authenticated users with author-level access and above to…
CVE-2026-8379High (7.5)0.41%—Jun 23, 2026
The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly enforce its nonce check on the file download handler, allowing unauthenticated attackers to download files uploaded by any user through…
CVE-2026-8378Medium (5.4)0.23%—Jun 23, 2026
The Frontend File Manager Plugin WordPress plugin through 23.6 does not sanitise nor escape a filename submitted to the frontend file-rename endpoint before storing it as post meta and rendering it back on the admin…
CVE-2026-5337Medium (6.5)0.34%—May 3, 2026
During the analysis, it was identified that authenticated attackers with Subscriber-level access or higher are able to perform an Insecure Direct Object Reference (IDOR) attack. This vulnerability exists because the…
CVE-2026-0829Medium (5.8)0.68%—Feb 17, 2026
The Frontend File Manager Plugin WordPress plugin through 23.5 allows unauthenticated users to send emails through the site without any security checks. This lets attackers use the WordPress site as an open relay for…
CVE-2026-1280High (7.5)0.34%—Jan 28, 2026
The Frontend File Manager Plugin for WordPress is vulnerable to unauthorized file sharing due to a missing capability check on the 'wpfm_send_file_in_email' AJAX action in all versions up to, and including, 23.5. This…
CVE-2025-14804High (7.7)0.27%—Jan 7, 2026
The Frontend File Manager Plugin WordPress plugin before 23.5 did not validate a path parameter and ownership of the file, allowing any authenticated users, such as subscribers to delete arbitrary files on the server
CVE-2025-13382Medium (4.3)0.23%—Nov 25, 2025
The Frontend File Manager Plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 23.4. This is due to the plugin not validating file ownership before processing file…
CVE-2023-7306High (7.5)0.32%—Jul 25, 2025
The Frontend File Manager Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wpfm_delete_multiple_files() function in all versions up to, and including, 21.5.…
CVE-2016-15042Critical (9.8)5.7%—Oct 16, 2024
The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulnerable to arbitrary file uploads due to missing file type validation via the…
CVE-2024-25903High (7.5)0.45%—Mar 17, 2024
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in N-Media Frontend File Manager.This issue affects Frontend File Manager: from n/a through 22.7.
CVE-2022-3125High (8.8)1.5%—Oct 3, 2022
The Frontend File Manager Plugin WordPress plugin before 21.3 allows any authenticated users, such as subscriber, to rename a file to an arbitrary extension, like PHP, which could allow them to basically be able to…
CVE-2022-3124Medium (5.3)8.3%—Oct 3, 2022
The Frontend File Manager Plugin WordPress plugin before 21.3 allows any unauthenticated user to rename uploaded files from users. Furthermore, due to the lack of validation in the destination filename, this could allow…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application5
  2. T1005 Data from Local System2
  3. T1210 Exploitation of Remote Services2
  4. T1565.001 Stored Data Manipulation2
  5. T1565.002 Transmitted Data Manipulation2
  6. T1505.003 Web Shell1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Najeebmedia