WordPress Plugin Vulnerabilities

Frontend File Manager < 23.5 - Subscriber+ Arbitrary File Deletion

Description

The plugin did not validate a path parameter and ownership of the file, allowing any authenticated users, such as subscribers to delete arbitrary files on the server

Proof of Concept

Affects Plugins

References

Classification

Type
FILE DELETION
CWE
CVSS

Miscellaneous

Original Researcher
Gregory Allegoet & Bakir Tučić
Submitter
Gregory Allegoet
Verified
Yes

Timeline

Publicly Published
2025-12-17 (about 15 days ago)
Added
2025-12-17 (about 14 days ago)
Last Updated
2025-12-17 (about 14 days ago)

Other