CVE-2025-13382

Frontend File Manager Plugin <= 23.4 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary File Renaming

The Frontend File Manager Plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 23.4. This is due to the plugin not validating file ownership before processing file rename requests in the '/wpfm/v1/file-rename' REST API endpoint. This makes it possible for authenticated attackers, with Subscriber-level access and above, to rename files uploaded by other users via the 'fileid' parameter.


We have discovered 15 live websites that are affected by CVE-2025-13382.

Run a Free Instant Scan




Affected Software

Product  Nmedia User File Uploader
Category Wordpress Plugins
Vulnerable Domains15 live websites (100% of Nmedia User File Uploader install base)
Vulnerable Versions
  • from 0 through 23.4
Vulnerable Versions Count1 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-639 Authorization Bypass Through User-Controlled Key



Details

  • Published - Nov 25, 2025
  • Updated - Nov 25, 2025

Credits

  • Rajesh Singh (finder)

Website Distribution by Country

Number of websites using CVE-2025-13382
United States6 websites



Italy2 websites
Russia2 websites
Australia1 websites
Colombia1 websites
Greece1 websites
Netherlands1 websites
Vietnam1 websites

Website Distribution by TLD

Number of websites using CVE-2025-13382
.com5 websites
.it2 websites
.com.au1 websites
.nl1 websites
.org1 websites
.ru1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-13382

Top websites that are affected by CVE-2025-13382. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.org United States*,***,***
*************.com United States*,***,***
*****.ru Russia**,***,***
***********.com United States**,***,***
********.biz Russia**,***,***
****************.com United States**,***,***
*************.nl Netherlands**,***,***
***********.***.vn Vietnam**,***,***
**************.com United States**,***,***
************.com United States**,***,***
See full domain list

FAQ

CVE-2025-13382 is Authorization Bypass Through User-Controlled Key in Nmedia User File Uploader
A total of 15 websites have been identified as vulnerable to CVE-2025-13382, based on global website indexing conducted by WebTechSurvey.
The Nmedia User File Uploader is affected by the CVE-2025-13382 vulnerability.
Nmedia User File Uploader versions up to and including 23.4 are vulnerable to CVE-2025-13382.