Executive brief
Multiple WordPress file manager plugins fail to properly validate the origin of cross-origin messages, allowing an attacker to run malicious JavaScript in an administrator's browser session. An unauthenticated attacker can exploit this by tricking a logged-in administrator into visiting a malicious webpage, leading to account compromise or administrative action being taken without consent.
Technical details
The vulnerability is a DOM-based XSS flaw in the bundled file-manager library (elFinder) used by these plugins. The vulnerable code accepts window.postMessage from any origin that matches as a leading string prefix of the site's address, bypassing origin validation. An unauthenticated attacker can craft a malicious page to send messages that execute arbitrary JavaScript in the admin's authenticated session, with no user interaction beyond visiting the attacker's page.
Affected products
- WordPress File Manager before 8.0.5
- WordPress FileOrganizer before 1.2.1
- WordPress File Manager Pro before 2.1.3
Timeline
- 2026-09-24: disclosed
- 2026-09-26: advisory