CVE-2026-8095Disclosure

LOWCVSS 8.1 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions up to and including 23.6. This is due to a case-sensitive bypass of the wpfm_dir_path parameter sanitization in the wpfm_file_meta_update AJAX handler, where supplying WPFM_DIR_PATH in uppercase evades the unset check and is normalized to wpfm_dir_path by sanitize_key() during update_post_meta(), allowing an attacker to overwrite the stored file path with an arbitrary filesystem path that is then passed directly to unlink() in delete_file_locally() without any directory containment validation. This makes it possible for authenticated attackers with Subscriber-level access to delete arbitrary files on the server, including sensitive files such as wp-config.php, potentially leading to full site takeover.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-73

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-06-28: 4Patch / Workaround · 2026-06-28: 1Technical Details · 2026-06-28: 406-28
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets3 URLs
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-8095 Authenticated Arbitrary File Deletion in Frontend File Manager Plugin WordPress 23.6 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8095

    Post summary

    The content briefly announces CVE-2026-8095, specifying that it enables authenticated arbitrary file deletion in the Frontend File Manager Plugin for WordPress 23.6. No PoC, exploit, active usage, or remediation information is included.

    00020116
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-8095 The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions up to and including 23.6. This is due to a case… https://www.cve.org/CVERecord?id=CVE-2026-8095 ----- Traducción: CVE-2026-8095 el … http://infoflow.cloud`

    Post summary

    The statement discloses a new CVE (CVE‑2026‑8095) affecting the WordPress Frontend File Manager Plugin, describing an authenticated arbitrary file deletion vulnerability for versions up to 23.6, without mentioning PoC, exploits, or patches.

    0001044
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-8095 The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions up to and including 23.6. This is due to a case… https://www.cve.org/CVERecord?id=CVE-2026-8095

    Post summary

    The post announces CVE‑2026‑8095 as an authenticated arbitrary file deletion flaw in the Frontend File Manager Plugin for WordPress up to version 23.6, without indicating lateral PoC, exploit code, active use, or fixes.

    00010856
    57.7K followersView on X
  • ADK Cyber@ADKCyber
    Patch

    WordPress Frontend File Manager Plugin vulnerable to authenticated arbitrary file deletion (CVE-2026-8095, CVSS 8.1). Update to latest version if used. via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability https://t.co/gjWIdJYA0K

    Post summary

    The tweet highlights CVE‑2026‑8095 affecting WordPress Frontend File Manager Plugin, explains it allows authenticated arbitrary file deletion, assigns CVSS 8.1, and urges users to update to the latest version.

    0000062
    92 followersView on X

Explore more