CVE-2025-27358: WordPress Frontend File Manager plugin <= 23.6 - Content Injection vulnerability
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in N-Media Frontend File Manager allows Code Injection.This issue affects Frontend File Manager: from n/a through 23.2.
Other sources
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Code Injection.This issue affects Frontend File Manager: from n/a through <= 23.6.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27358?
CVE-2025-27358 is a medium severity vulnerability due to improper neutralization of script-related HTML tags in a web page.
How do I fix CVE-2025-27358?
To fix CVE-2025-27358, upgrade to a patched version of Mndpsingh287 Frontend File Manager beyond version 23.2.
What platforms are affected by CVE-2025-27358?
CVE-2025-27358 affects Mndpsingh287 Frontend File Manager and WordPress Frontend File Manager versions up to and including 23.2.
What type of vulnerability is CVE-2025-27358?
CVE-2025-27358 is classified as a Basic XSS (Cross-site Scripting) vulnerability.
Can CVE-2025-27358 lead to code injection?
Yes, CVE-2025-27358 allows for code injection due to improper handling of script-related HTML tags.