
CVE-2026-1280 The Frontend File Manager Plugin for WordPress is vulnerable to unauthorized file sharing due to a missing capability check on the 'wpfm_send_file_in_email' AJAX action… https://www.cve.org/CVERecord?id=CVE-2026-1280
Post summary
CVE‑2026‑1280 reveals an unauthorized file‐sharing flaw in the Frontend File Manager Plugin for WordPress caused by a missing capability check on an AJAX action; no PoC, exploit, or patch is disclosed.
