Extension WordPress

Vulnérabilités Frontend File Manager Plugin

Cette page rassemble les failles publiées pour Frontend File Manager Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.

30Vulnérabilités
5Critiques
24Avec correctif
9,9CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Frontend File Manager Plugin

30 fiches

CVE-2026-8095 Élevée · 8,1
Frontend File Manager Plugin

Frontend File Manager Plugin <= 23.6 – Authenticated (Subscriber+) Arbitrary File Deletion

The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions up to and including 23.6. This is due to a case-sensitive bypass of the wpfm_dir_path parameter sanitization in the wpfm_file_meta_update AJAX…

Versions affectées

*-23.6

Correctif

Non indiqué

Publication

27/06/2026

CVE-2026-8379 Moyenne · 5,3
Frontend File Manager Plugin

Frontend File Manager Plugin <= 23.6 – Missing Authorization to Unauthenticated File Download

The Frontend File Manager Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'wpfm_download' action in all versions up to, and including, 23.6. This makes it possible for unauthenticated attackers…

Versions affectées

*-23.6

Correctif

Non indiqué

Publication

25/06/2026

CVE-2026-8378 Moyenne · 6,4
Frontend File Manager Plugin

Frontend File Manager Plugin <= 23.6 – Authenticated (Subscriber+) Stored Cross-Site Scripting

The Frontend File Manager Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 23.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level…

Versions affectées

*-23.6

Correctif

Non indiqué

Publication

25/06/2026

CVE-2026-5337 Moyenne · 4,3
Frontend File Manager Plugin

Frontend File Manager <= 23.6 – Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Download Access

The Frontend File Manager Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 23.6 due to missing validation on a user controlled key. This makes it possible for authenticated…

Versions affectées

*-23.6

Correctif

Non indiqué

Publication

11/04/2026

CVE-2026-1280 Élevée · 7,5
Frontend File Manager Plugin

Frontend File Manager Plugin <= 23.5 – Missing Authorization to Unauthenticated Arbitrary File Sharing via 'file_id' Parameter

The Frontend File Manager Plugin for WordPress is vulnerable to unauthorized file sharing due to a missing capability check on the 'wpfm_send_file_in_email' AJAX action in all versions up to, and including, 23.5. This makes it possible for unauthenticated…

Versions affectées

*-23.5

Correctif

23.6

Publication

27/01/2026

CVE-2025-14804 Élevée · 8,1
Frontend File Manager Plugin

Frontend File Manager <= 23.4 – Authenticated (Subscriber+) Arbitrary File Deletion

The Frontend File Manager Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 23.4. This makes it possible for authenticated attackers, with Subscriber-level access…

Versions affectées

*-23.4

Correctif

23.5

Publication

17/12/2025

CVE-2025-13382 Moyenne · 4,3
Frontend File Manager Plugin

Frontend File Manager Plugin <= 23.4 – Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary File Renaming

The Frontend File Manager Plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 23.4. This is due to the plugin not validating file ownership before processing file rename requests in…

Versions affectées

*-23.4

Correctif

23.5

Publication

24/11/2025

CVE-2023-7306 Élevée · 7,5
Frontend File Manager Plugin

Frontend File Manager <= 21.5 – Missing Authorization to Unauthenticated Arbitrary Post Deletion

The Frontend File Manager Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wpfm_delete_multiple_files() function in all versions up to, and including, 21.5. This makes it possible for…

Versions affectées

*-21.5

Correctif

22.0

Publication

24/07/2025

CVE-2025-27358 Moyenne · 4,3
Frontend File Manager Plugin

Frontend File Manager <= 23.2 – Missing Authorization to Authenticated (Subscriber+) Content Injection

The Frontend File Manager Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 23.2. This makes it possible for authenticated attackers, with…

Versions affectées

*-23.2

Correctif

Non indiqué

Publication

04/07/2025

CVE-2022-3125 Élevée · 8,8
Frontend File Manager Plugin

Frontend File Manager <= 21.2 – Authenticated (Subscriber+) Arbitrary File Upload

The Frontend File Manager plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 21.2. The vulnerability makes it possible for authenticated attackers, with subscriber-level permissions and above, to upload arbitrary files on…

Versions affectées

*-21.2

Correctif

21.3

Publication

07/09/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités