Executive brief
The Frontend File Manager Plugin for WordPress is missing CSRF protection on a file metadata update action, allowing attackers to modify uploaded file metadata through a crafted webpage. This can be exploited to inject malicious download hashes that bypass file access controls, enabling unauthorized file downloads. When guest uploads are enabled, the vulnerability can be exploited without authentication against any user's files.
Technical details
The plugin fails to validate WordPress nonces on the wpfm_file_meta_update AJAX action, which allows an attacker to inject arbitrary file hashes into a target's file metadata via a CSRF attack. In default configuration, this requires a logged-in victim to visit an attacker-controlled page; the injected hash then bypasses the download gate on the wpfm_download action. When the "Allow Guest Upload" option is enabled (non-default), the ownership check is removed entirely, allowing unauthenticated attackers to modify any file's metadata and download arbitrary uploaded files. No patch is currently available.
Affected products
- <UNKNOWN> Frontend File Manager Plugin through 23.6
Timeline
- 2026-07-21: disclosed