The Frontend File Manager Plugin WordPress plugin through 23.5 allows unauthenticated users to send emails through the site without any security checks. This lets attackers use the WordPress site as an open relay for spam or phishing emails to anyone. Attackers can also guess file IDs to access and share uploaded files without permission, exposing sensitive information.
Metrics
Affected Vendors & Products
References
History
Tue, 17 Feb 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Frontend File Manager Plugin WordPress plugin through 23.5 allows unauthenticated users to send emails through the site without any security checks. This lets attackers use the WordPress site as an open relay for spam or phishing emails to anyone. Attackers can also guess file IDs to access and share uploaded files without permission, exposing sensitive information. | |
| Title | Frontend File Manager Plugin <= 23.5 - Unauthenticated Arbitrary Email Sending | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-02-17T06:00:06.506Z
Reserved: 2026-01-09T20:13:31.418Z
Link: CVE-2026-0829
No data.
Status : Received
Published: 2026-02-17T07:16:31.883
Modified: 2026-02-17T07:16:31.883
Link: CVE-2026-0829
No data.
OpenCVE Enrichment
No data.