Executive brief
The Frontend File Manager plugin for WordPress, which allows users to upload and manage files, contains a security flaw in its download system. An unauthorized person can bypass security checks and download any file uploaded by any user on the site. This could lead to the exposure of sensitive documents, private data, or proprietary information stored within the plugin.
Technical details
The vulnerability is an Insecure Direct Object Reference (IDOR) and authentication bypass in the file download handler. The plugin uses a nonce check to protect downloads, but this check is bypassed if the 'nm_file_by_email' parameter is present in the request. An unauthenticated attacker can exploit this by sending a crafted GET request to the download endpoint and iterating through 'file_id' values. This allows for the bulk unauthorized download of all files managed by the plugin. As of the advisory date, no fix has been released.
Affected products
- nmedia-user-file-uploader Frontend File Manager Plugin <= 23.6
Timeline
- 2026-06-02: disclosed: Publicly published by WPScan
- 2026-06-23: advisory: CVE published to NVD dataset