
PEACH
Un cadre d’isolation des locataires
CVE-2026-16292 is a Cross-Site Request Forgery (CSRF) vulnerability in the Frontend File Manager Plugin for WordPress (plugin slug: nmedia-user-file-uploader) affecting all versions through 23.6. The flaw allows attackers to modify file metadata of uploaded files via CSRF, which can be leveraged to download those files; when guest uploads are enabled, the action is reachable unauthenticated against any user's file. It was publicly disclosed on July 21, 2026, and added to NVD on August 2, 2026. The CVSS score is 5.4 (Medium) per WPScan, with the vulnerability assigned CWE-352 (WPScan, GitHub Advisory).
The root cause is missing nonce validation (CWE-352: Cross-Site Request Forgery) on a file-metadata update action within the plugin. In WordPress, nonces are used to verify the authenticity of requests; without this check, an attacker can craft a malicious web page or link that, when visited by a logged-in user, silently submits a forged request to modify the metadata of that user's uploaded files. The modified metadata can then be leveraged to facilitate unauthorized file downloads. When guest uploads are enabled, the vulnerable action is accessible without any authentication, allowing direct exploitation against any user's files without requiring a CSRF vector (WPScan). A proof-of-concept was scheduled for public release on August 4, 2026, to allow time for users to update (WPScan).
Successful exploitation allows an attacker to modify the metadata of files uploaded by any user, which can be leveraged to enable unauthorized downloads of those files — potentially exposing sensitive or private documents stored via the plugin. In the guest uploads scenario, this is achievable without any authentication, broadening the attack surface to all WordPress sites with that feature enabled. The primary impact is unauthorized access to confidential files (confidentiality breach), with limited integrity impact through metadata manipulation (WPScan, GitHub Advisory).
nmedia-user-file-uploader) at version 23.6 or earlier using tools like WPScan or by inspecting plugin directories.nmedia-user-file-uploader) from unauthenticated sessions or unfamiliar IP addresses; unusual file download requests following metadata update requests.Update the Frontend File Manager Plugin to version 23.7 or later, which addresses the missing nonce validation. As an interim measure, disable guest uploads if the feature is not required, as this eliminates the unauthenticated attack vector. Additionally, consider deploying a Web Application Firewall (WAF) with CSRF protection rules, and implement server-side validation of file access permissions. The vulnerability was discovered by Yaswanth Reddy Sunkara and verified by WPScan (WPScan).
The vulnerability was reported and verified by WPScan, with the original researcher credited as Yaswanth Reddy Sunkara. WPScan delayed PoC publication until August 4, 2026, to allow site administrators time to apply the patch — a standard responsible disclosure practice. No significant broader media coverage or notable researcher commentary beyond the WPScan advisory has been identified at this time (WPScan).
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."