CVE-2026-5337
Frontend File Manager Plugin
Minimum safe version
23.6
Update to 23.6 or later to address 47 fixable vulnerabilities
CVE-2025-57921
Frontend File Manager Plugin <= 23.5 - Missing Authorization to Unauthenticated Arbitrary File Sharing via 'file_id' Parameter
Frontend File Manager <= 23.5 - Missing Authorization
CVE-2026-25005
CVE-2025-14804
CVE-2025-13382
CVE-2025-64265
WordPress Frontend File Manager plugin <= 23.6 - Content Injection vulnerability
Frontend File Manager <= 21.5 - Missing Authorization to Unauthenticated Arbitrary Post Deletion
CVE-2016-15042
CVE-2024-25903
CVE-2023-5105
Frontend File Manager < 21.4 - Arbitrary Settings Update via CSRF
N-Media File Uploader < 2.0 Arbitrary File Upload
N-Media File Uploader <= 3.7 - Arbitrary File Upload
CVE-2015-4693
Front end file upload and manager Plugin <= 3.9 - Arbitrary File Upload
CVE-2021-4368
CVE-2021-4369
CVE-2021-4351
CVE-2021-4356
CVE-2021-4365
CVE-2021-4359
CVE-2021-4344
CVE-2021-4350
Frontend File Manager <= 3.7 - Arbitrary File Upload
Frontend File Manager < 4.0 & N-Media Post Front-end Form < 1.1 & - Arbitrary File Upload
Frontend File Manager <= 18.2 - Unauthenticated Content Injection
Frontend File Manager <= 18.2 - Authenticated Settings Change leading to Arbitrary File Upload
Frontend File Manager <= 18.2 - Unauthenticated Stored Cross-Site Scripting
Frontend File Manager Plugin <= 18.2 - Unauthenticated Arbitrary Post Deletion
Frontend File Manager <= 18.2 - Unauthenticated Arbitrary File Download
Frontend File Manager <= 18.2 - Unauthenticated Post Meta Change
Frontend File Manager <= 18.2 - Unauthenticated HTML Injection leading to Spam Emails
Frontend File Manager <= 18.2 - Privilege Escalation
Frontend File Manager <= 21.3 - Cross-Site Request Forgery to Plugin Settings Update
WordPress Frontend File Manager plugin <= 21.3 - Arbitrary Settings Update via Cross-Site Request Forgery (CSRF) vulnerability
CVE-2022-3126
CVE-2022-3124
CVE-2022-3125
WordPress N-Media File Uploader Plugin <= 3.7 - Arbitrary File Upload
WordPress N-Media File Uploader Plugin <= 1.9 - Arbitrary File Upload
WordPress Front End File Upload And Manager Plugin <= 3.9 - Arbitrary File Upload
WordPress Frontend File Manager plugin <= 18.2 - Unauthenticated Arbitrary Post Deletion vulnerability
WordPress Frontend File Manager plugin <= 18.2 - Unauthenticated Post Meta Change and Arbitrary File Download vulnerability
WordPress Frontend File Manager plugin <= 18.2 - Unauthenticated HTML Injection vulnerability
WordPress Frontend File Manager plugin <= 18.2 - Authenticated Settings Change and Arbitrary File Upload vulnerabilities
WordPress Frontend File Manager plugin <= 18.2 - Unauthenticated Content Injection and Stored XSS vulnerabilities
WordPress Frontend File Manager plugin <= 17.1 - Privilege Escalation vulnerability
CVE-2014-5324