PT-2025-30738 · WordPress · Frontend File Manager Plugin

David Dewes

+1

·

Published

2025-07-25

·

Updated

2025-07-30

·

CVE-2023-7306

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Frontend File Manager Plugin for WordPress versions prior to 21.5
Description The plugin is susceptible to unauthorized data loss due to a missing capability check within the wpfm delete multiple files() function. This allows unauthenticated attackers to delete arbitrary posts.
Recommendations Update the Frontend File Manager Plugin to a version later than 21.5.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-7306

Affected Products

Frontend File Manager Plugin