CVE-2023-5105: Najeebmedia Frontend File Manager Plugin

Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.

The Frontend File Manager Plugin WordPress plugin before 22.6 has a vulnerability that allows an Editor+ user to bypass the file download logic and download files such as `wp-config.php`

Affected products

  • Najeebmedia Frontend File Manager Plugin: before 22.6 (fixed in 22.6)

Published 2023-12-04. Last modified 2026-06-17.