momo安全漏洞库

多模块数据检索平台

登录 注册
返回列表

CVE-2026-0829: Frontend File Manager Plugin <= 23.5 - Unauthenticated Arbitrary Email Sending

CVE: CVE-2026-0829
CNVD: 暂无
CNNVD: 暂无
漏洞类型: 命令执行
漏洞等级: 高危
年份: 2026
POC_ID: 暂无
漏洞描述
Frontend File Manager Plugin WordPress plugin through 23.5 contains an open relay and unauthorized file access vulnerability caused by lack of authentication and security checks, letting unauthenticated attackers send emails and access files, exploit requires no authentication. [已公开] id: CVE-2026-0829 info: name: Frontend File Manager Plugin <= 23.5 - Unauthenticated Arbitrary Email Sending author: 0x_Akoko severity: high description: | Frontend File Manager Plugin WordPress plugin through 23.5 contains an open relay and unauthorized file access vulnerability caused by lack of authentication and security checks, letting unauthenticated attackers send emails and access files, exploit requires no authentication. impact: | Unauthenticated attackers can send spam emails and access sensitive uploaded files, leading to information disclosure and abuse of email functionality. remediation: | Update to the latest version beyond 23.5. reference: - https://www.wordfence.com/threat-intel/vulnerabilities/id/e739e7d3-756a-4c93-9ca7-f7b9f9657033 - https://wpscan.com/vulnerability/57d62cea-cfb8-4421-a209-e64a015ad225/ - https://plugins.trac.wordpress.org/browser/nmedia-user-file-uploader/tags/23.5
影响范围
未知
漏洞详情
登录后可查看漏洞详情。请先 登录注册
漏洞 POC
登录后可查看漏洞 POC。请先 登录注册
修复建议
暂无