PoC Index

CVE-2026-8379

HIGH 7.5EPSS 0.4%

The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly enforce its nonce check on the file download handler, allowing unauthenticated attackers to download files uploaded by any user through the Frontend File Manager Plugin WordPress plugin through 23.6 by iterating identifiers.

CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
0.41% chance of exploitation in the next 30 days, 34th percentile
Published
2026-06-23

Proof-of-concept exploits (1)

References

Related