Known Vulnerabilities for Frontend File Manager Plugin by Najeebmedia
Listed below are 10 of the newest known vulnerabilities associated with "Frontend File Manager Plugin" by "Najeebmedia".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-8380 json | The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly verify ownership of every targeted post befo... | Not Provided | 2026-06-26 | 2026-06-26 |
| CVE-2026-8379 json | The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly enforce its nonce check on the file download... | Not Provided | 2026-06-23 | 2026-06-23 |
| CVE-2026-8378 json | The Frontend File Manager Plugin WordPress plugin through 23.6 does not sanitise nor escape a filename submitted to the front... | Not Provided | 2026-06-23 | 2026-06-23 |
| CVE-2026-5337 json | During the analysis, it was identified that authenticated attackers with Subscriber-level access or higher are able to perfor... | Not Provided | 2026-05-03 | 2026-05-04 |
| CVE-2025-13382 json | The Frontend File Manager Plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and i... | Not Provided | 2025-11-25 | 2026-04-08 |
| CVE-2023-5105 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.5 - MEDIUM | 2023-12-04 | 2023-12-07 |
| CVE-2022-3126 json | The Frontend File Manager Plugin WordPress plugin before 21.4 does not have CSRF check when uploading files, which could allo... | 4.3 - MEDIUM | 2022-10-17 | 2022-10-21 |
| CVE-2022-2356 json | The Frontend File Manager & Sharing WordPress plugin before 1.1.3 does not filter file extensions when letting users upload f... | 4.3 - MEDIUM | 2022-08-08 | 2026-06-23 |
| CVE-2022-1961 json | The Google Tag Manager for WordPress (GTM4WP) plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escapin... | 4.3 - MEDIUM | 2022-06-13 | 2026-04-08 |
| CVE-2022-1707 json | The Google Tag Manager for WordPress plugin for WordPress is vulnerable to reflected Cross-Site Scripting via the s parameter... | 4.3 - MEDIUM | 2022-06-13 | 2026-04-08 |