Junglewise Threat Intelligence

CVE-2026-85081: WordPress File Manager plugins DOM-based XSS via postMessage origin bypass

CVE-2026-85081 · Severity: info · Published 2026-09-26

Vendors: Wordpress.

Executive brief

Multiple WordPress file manager plugins fail to properly validate the origin of cross-origin messages, allowing an attacker to run malicious JavaScript in an administrator's browser session. An unauthenticated attacker can exploit this by tricking a logged-in administrator into visiting a malicious webpage, leading to account compromise or administrative action being taken without consent.

Technical details

The vulnerability is a DOM-based XSS flaw in the bundled file-manager library (elFinder) used by these plugins. The vulnerable code accepts window.postMessage from any origin that matches as a leading string prefix of the site's address, bypassing origin validation. An unauthenticated attacker can craft a malicious page to send messages that execute arbitrary JavaScript in the admin's authenticated session, with no user interaction beyond visiting the attacker's page.

Affected products

  • WordPress File Manager before 8.0.5
  • WordPress FileOrganizer before 1.2.1
  • WordPress File Manager Pro before 2.1.3

Timeline

  • 2026-09-24: disclosed
  • 2026-09-26: advisory

References