CVE Database
/

CVE-2026-0829

Back to search

CVE-2026-0829

Published: Feb 17, 2026

Modified: Apr 2, 2026

PUBLISHED

Description

The Frontend File Manager Plugin WordPress plugin through 23.5 allows unauthenticated users to send emails through the site without any security checks. This lets attackers use the WordPress site as an open relay for spam or phishing emails to anyone. Attackers can also guess file IDs to access and share uploaded files without permission, exposing sensitive information.

VendorProductVersions

Unknown

Frontend File Manager Plugin

affected
0 - <= 23.5

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now