CVE-2025-64265: WordPress Frontend File Manager plugin <= 23.2 - Broken Access Control vulnerability
Missing Authorization vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Frontend File Manager: from n/a through <= 23.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64265?
CVE-2025-64265 is classified as a critical vulnerability due to the potential for unauthorized access and exploitation.
How do I fix CVE-2025-64265?
To mitigate CVE-2025-64265, update the N-Media Frontend File Manager plugin to version 23.3 or later.
What types of systems are affected by CVE-2025-64265?
CVE-2025-64265 affects N-Media Frontend File Manager versions up to and including 23.2.
What is the main issue with CVE-2025-64265?
CVE-2025-64265 involves missing authorization checks that may allow attackers to exploit incorrectly configured access control.
Can CVE-2025-64265 be exploited remotely?
Yes, CVE-2025-64265 can be exploited remotely by attackers if the application is exposed to the internet.