THREAT OPS › Threat News › [NVD] CVE-2026-16292 — The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing an attacker to modify the metadata of a logged-in user's uploaded file via a CSRF attack, which can be leveraged to download that
[NVD] CVE-2026-16292 — The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing an attacker to modify the metadata of a logged-in user's uploaded file via a CSRF attack, which can be leveraged to download that
CVE-2026-16292 CVSS: None Published: 2026-08-02T06:16:40.673
The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing an attacker to modify the metadata of a logged-in user's uploaded file via a CSRF attack, which can be leveraged to download that file. When guest uploads are enabled, the same action is
Indicators of compromise
- CVE-2026-16292cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-16292