Impact
The Frontend File Manager Plugin does not verify that a user owns a post before it is permanently deleted. Authenticated users with author-level permission or higher can delete any post or page. If the "Allow guest uploads" option is enabled by an administrator, unauthenticated visitors can also trigger this deletion action. This flaw allows attackers to remove legitimate content, potentially causing loss of data and a denial‑of‑service condition for site owners.
Affected Systems
WordPress installations that use the Frontend File Manager Plugin version 23.6 or earlier are affected. Users with the author role or higher are capable of exploiting the flaw, and if the attacker can access the plugin’s guest upload feature on a site where it is enabled, the deletion capability can be abused without authentication.
Risk and Exploitability
The vulnerability requires at least author‑level access to the site or the ability to upload files as a guest; it does not rely on arbitrary code execution. No public exploits have been disclosed, and the EPSS score is not available. The flaw is not listed in CISA’s KEV catalog, but the potential for content loss and site disruption makes it a high‑risk issue for affected WordPress sites. Site owners should consider the risk of unauthorized content removal when evaluating their security posture.
OpenCVE Enrichment