The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing an attacker to modify the metadata of a logged-in user's uploaded file via a CSRF attack, which can be leveraged to download that file. When guest uploads are enabled, the same action is reachable unauthenticated against any user's file.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 02 Aug 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Frontend File Manager Plugin
Frontend File Manager Plugin frontend File Manager Plugin Wordpress Wordpress wordpress |
|
| Vendors & Products |
Frontend File Manager Plugin
Frontend File Manager Plugin frontend File Manager Plugin Wordpress Wordpress wordpress |
Sun, 02 Aug 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing an attacker to modify the metadata of a logged-in user's uploaded file via a CSRF attack, which can be leveraged to download that file. When guest uploads are enabled, the same action is reachable unauthenticated against any user's file. | |
| Title | Frontend File Manager Plugin <= 23.6 - File Metadata Update via CSRF | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-02T06:00:12.411Z
Reserved: 2026-07-20T12:21:54.376Z
Link: CVE-2026-16292
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-02T07:45:03Z
Weaknesses
No weakness.