Description
The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing an attacker to modify the metadata of a logged-in user's uploaded file via a CSRF attack, which can be leveraged to download that file. When guest uploads are enabled, the same action is reachable unauthenticated against any user's file.
Published:
2026-08-02
Score:
n/a
EPSS:
n/a
KEV:
No
Impact:
n/a
Action:
n/a
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Sun, 02 Aug 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Frontend File Manager Plugin
Frontend File Manager Plugin frontend File Manager Plugin Wordpress Wordpress wordpress |
|
| Vendors & Products |
Frontend File Manager Plugin
Frontend File Manager Plugin frontend File Manager Plugin Wordpress Wordpress wordpress |
Sun, 02 Aug 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing an attacker to modify the metadata of a logged-in user's uploaded file via a CSRF attack, which can be leveraged to download that file. When guest uploads are enabled, the same action is reachable unauthenticated against any user's file. | |
| Title | Frontend File Manager Plugin <= 23.6 - File Metadata Update via CSRF | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-02T06:00:12.411Z
Reserved: 2026-07-20T12:21:54.376Z
Link: CVE-2026-16292
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-02T07:45:03Z
Weaknesses
No weakness.