CVE-2026-12277 UNKNOWN

CVE-2026-12277

Published: 2026-07-07

Description

The Frontend File Manager Plugin WordPress plugin through 23.6 does not validate a file path derived from user input before deleting the referenced file, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php) when guest upload mode is enabled. Deleting wp-config.php forces the site into its setup routine, which can be leveraged toward a full site takeover.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…