The Frontend File Manager Plugin WordPress plugin through 23.5 allows unauthenticated users to send emails through the site without any security checks. This lets attackers use the WordPress site as an open relay for spam or phishing emails to anyone. Attackers can also guess file IDs to access and share uploaded files without permission, exposing sensitive information.
Metrics
Affected Vendors & Products
References
History
Wed, 18 Feb 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Frontend File Manager Plugin
Frontend File Manager Plugin frontend File Manager Plugin Wordpress Wordpress wordpress |
|
| Vendors & Products |
Frontend File Manager Plugin
Frontend File Manager Plugin frontend File Manager Plugin Wordpress Wordpress wordpress |
Tue, 17 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-862 |
Tue, 17 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 17 Feb 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Frontend File Manager Plugin WordPress plugin through 23.5 allows unauthenticated users to send emails through the site without any security checks. This lets attackers use the WordPress site as an open relay for spam or phishing emails to anyone. Attackers can also guess file IDs to access and share uploaded files without permission, exposing sensitive information. | |
| Title | Frontend File Manager Plugin <= 23.5 - Unauthenticated Arbitrary Email Sending | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published: 2026-02-17T06:00:06.506Z
Updated: 2026-02-17T18:19:47.377Z
Reserved: 2026-01-09T20:13:31.418Z
Link: CVE-2026-0829
Updated: 2026-02-17T15:07:22.828Z
Status : Received
Published: 2026-02-17T07:16:31.883
Modified: 2026-02-17T19:21:56.050
Link: CVE-2026-0829
No data.