WordPress Plugin Vulnerabilities

Frontend File Manager Plugin <= 23.5 - Unauthenticated Arbitrary Email Sending

Description

The plugin allows unauthenticated users to send emails through the site without any security checks. This lets attackers use the WordPress site as an open relay for spam or phishing emails to anyone. Attackers can also guess file IDs to access and share uploaded files without permission, exposing sensitive information.

Proof of Concept

Affects Plugins

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
yiğit ibrahim sağlam
Submitter
yiğit ibrahim sağlam
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-01-27 (about 21 days ago)
Added
2026-01-27 (about 21 days ago)
Last Updated
2026-01-27 (about 21 days ago)

Other