What is CVE-2026-16292?
The Frontend File Manager Plugin for WordPress up to version 23.6 lacks nonce validation on a file metadata update action. This allows an attacker to modify metadata of a logged-in user's uploaded file via a CSRF attack, which can be leveraged to download that file. It is recommended to update the plugin to the latest version.
Azərbaycanca: WordPress üçün Frontend File Manager Plugin-in 23.6-ya qədər versiyalarında fayl metadata yeniləmə əməliyyatında nonce yoxlaması aparılmır. Bu boşluq autentifikasiya olunmuş istifadəçinin yüklədiyi faylın metadatasını dəyişməyə və faylı endirməyə imkan verir. Plugin-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-352
FAQ2
Up to which version is the Frontend File Manager Plugin affected by CVE-2026-16292?
The Frontend File Manager Plugin for WordPress up to version 23.6 is affected by this vulnerability.
What can an attacker do by exploiting CVE-2026-16292?
An attacker can modify metadata of a logged-in user's uploaded file, which can be leveraged to download that file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.