Vulnerability record · CVE-2025-14804 · published 7 January 2026
CVE-2025-14804: The Frontend File Manager Plugin WordPress plugin before 23.5 did not validate a path parameter and ownership …
The Frontend File Manager Plugin WordPress plugin before 23.5 did not validate a path parameter and ownership of the file, allowing any authenticated users, such as subscribers to delete arbitrary files on the server
Description
The Frontend File Manager Plugin WordPress plugin before 23.5 did not validate a path parameter and ownership of the file, allowing any authenticated users, such as subscribers to delete arbitrary files on the server
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
References
Track CVE-2025-14804 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2025-14804), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.