CVE-2026-0829Patch

LOWCVSS 5.8 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The Frontend File Manager Plugin WordPress plugin through 23.5 allows unauthenticated users to send emails through the site without any security checks. This lets attackers use the WordPress site as an open relay for spam or phishing emails to anyone. Attackers can also guess file IDs to access and share uploaded files without permission, exposing sensitive information.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-17); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-17: 1Mentions · 2026-02-25: 1PoC Mentioned / Linked · 2026-02-25: 1Patch / Workaround · 2026-02-17: 1Technical Details · 2026-02-17: 1Technical Details · 2026-02-25: 102-1702-25
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-171
Patch1
2026-02-251
Disclosure1
Full discourse2 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-0829 - high 🚨 Frontend File Manager Plugin <= 23.5 - Unauthenticated Arbitrary Email Sending > Frontend File Manager Plugin WordPress plugin through 23.5 contains an open relay and... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-0829 @pdnuclei #NucleiTem...

    Post summary

    CVE-2026-0829 reveals an unauthenticated arbitrary email sending vulnerability (open relay) in Frontend File Manager Plugin up to version 23.5, with a link to additional details provided.

    00000188
    890 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 HIGH severity: CVE-2026-0829 in Frontend File Manager plugin (≤23.5) lets unauth'd attackers send emails & access files on WordPress sites. Remove or update plugin ASAP! 📧 https://radar.offseq.com/threat/cve-2026-0829-cwe-862-missing-authorization-in-fro-323c4855 #OffSeq #Wo... https://t.co/pO1iVtGztt

    Post summary

    A new high‑severity CVE‑2026‑0829 in the Frontend File Manager plugin allows unauthenticated attackers to send emails and read files; administrators are urged to update or remove the plugin.

    0000046
    265 followersView on X

Explore more