The Frontend File Manager Plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 23.4. This is due to the plugin not validating file ownership before processing file rename requests in the '/wpfm/v1/file-rename' REST API endpoint. This makes it possible for authenticated attackers, with Subscriber-level access and above, to rename files uploaded by other users via the 'fileid' parameter.
Metrics
Affected Vendors & Products
References
History
Wed, 26 Nov 2025 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Najeebmedia
Najeebmedia frontend File Manager Plugin Wordpress Wordpress wordpress |
|
| Vendors & Products |
Najeebmedia
Najeebmedia frontend File Manager Plugin Wordpress Wordpress wordpress |
Tue, 25 Nov 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Nov 2025 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Frontend File Manager Plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 23.4. This is due to the plugin not validating file ownership before processing file rename requests in the '/wpfm/v1/file-rename' REST API endpoint. This makes it possible for authenticated attackers, with Subscriber-level access and above, to rename files uploaded by other users via the 'fileid' parameter. | |
| Title | Frontend File Manager Plugin <= 23.4 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary File Renaming | |
| Weaknesses | CWE-639 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-11-25T07:28:24.012Z
Updated: 2025-11-25T14:53:21.862Z
Reserved: 2025-11-18T20:35:25.380Z
Link: CVE-2025-13382
Updated: 2025-11-25T14:53:19.087Z
Status : Awaiting Analysis
Published: 2025-11-25T08:15:50.253
Modified: 2025-11-25T22:16:16.690
Link: CVE-2025-13382
No data.