CVE-2023-7306: Nmedia Frontend File Manager Plugin

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

The Frontend File Manager Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wpfm_delete_multiple_files() function in all versions up to, and including, 21.5. This makes it possible for unauthenticated attackers to delete arbitrary posts.

Affected products

  • Nmedia Frontend File Manager Plugin: up to and including 21.5

Published 2025-07-25. Last modified 2026-06-17.