WordPress security by component
Frontend File Manager Plugin
Plugin description
Frontend File Manager Plugin is a WordPress component with 18 published CVE records in this archive. The latest tracked vulnerability was published Jul 07, 2026; the highest CVE/CNA score is 9.9.
Plugin slug:
frontend-file-manager-pluginLatest vulnerability
CVE-2026-12277: Frontend File Manager Plugin: Arbitrary file deletion
Frontend File Manager Plugin is affected by arbitrary file deletion. The vulnerable path is reachable without authentication. A successful request can remove files outside the intended scope and may make the site unavailable. The published affected range is <= 23.6.
| Safe version |
|
||
|---|---|---|---|
| Jul 07, 2026 |
CVE-2026-12277
Frontend File Manager Plugin: Arbitrary file deletion
Frontend File Manager Plugin is affected by arbitrary file deletion. The vulnerable path is reachable without authentication. A successful request can remove files outside the intended scope and may make the site unavailable. The published affected range is <= 23.6.
|
> 23.6 |
CVE8.7
NVDPending
|
| Jun 26, 2026 |
CVE-2026-8380
Frontend File Manager Plugin: A security weakness
Frontend File Manager Plugin is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 23.6.
|
> 23.6 |
CVE6.5
NVDPending
|
| Jun 23, 2026 |
CVE-2026-8379
Frontend File Manager Plugin: A security weakness
Frontend File Manager Plugin is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 23.6.
|
> 23.6 |
CVE7.5
NVDPending
|
| Jun 23, 2026 |
CVE-2026-8378
Frontend File Manager Plugin: Cross-site scripting
Frontend File Manager Plugin is affected by cross-site scripting. Exploitation requires at least subscriber-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 23.6.
|
> 23.6 |
CVE5.4
NVDPending
|
| May 03, 2026 |
CVE-2026-5337
Frontend File Manager Plugin: A security weakness
Frontend File Manager Plugin is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 23.6.
|
> 23.6 |
CVE6.5
NVDPending
|
| Feb 17, 2026 |
CVE-2026-0829
Frontend File Manager Plugin: A security weakness
Frontend File Manager Plugin is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.8
NVDPending
|
| Jan 07, 2026 |
CVE-2025-14804
Frontend File Manager Plugin: Arbitrary file deletion
Frontend File Manager Plugin is affected by arbitrary file deletion. Exposure depends on how the affected operation is made reachable by the site. A successful request can remove files outside the intended scope and may make the site unavailable.
|
See mitigation notes |
CVE7.7
NVDPending
|
| Jul 25, 2025 |
CVE-2023-7306
Frontend File Manager Plugin: A security weakness
Frontend File Manager Plugin is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Dec 04, 2023 |
CVE-2023-5105
Frontend File Manager Plugin: A security weakness
Frontend File Manager Plugin is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Jun 07, 2023 |
CVE-2021-4369
Frontend File Manager: A security weakness
Frontend File Manager is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.8
NVD5.3
|
| Jun 07, 2023 |
CVE-2021-4368
Frontend File Manager: Code execution
Frontend File Manager is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE9.9
NVD8.8
|
| Jun 07, 2023 |
CVE-2021-4365
Frontend File Manager: Cross-site scripting
Frontend File Manager is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.2
NVD6.1
|
| Jun 07, 2023 |
CVE-2021-4359
Frontend File Manager: A security weakness
Frontend File Manager is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD5.3
|
| Jun 07, 2023 |
CVE-2021-4356
Frontend File Manager: A security weakness
Frontend File Manager is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE9.0
NVD9.8
|
| Jun 07, 2023 |
CVE-2021-4351
Frontend File Manager: A security weakness
Frontend File Manager is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.8
NVD5.3
|
| Jun 07, 2023 |
CVE-2021-4350
Frontend File Manager: A security weakness
Frontend File Manager is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.2
NVD5.3
|
| Jun 07, 2023 |
CVE-2021-4344
Frontend File Manager: Privilege escalation or authentication bypass
Frontend File Manager is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Oct 17, 2022 |
CVE-2022-3126
Frontend File Manager Plugin: Cross-site request forgery
Frontend File Manager Plugin is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD4.3
|