CVE-2025-57921

WordPress Frontend File Manager Plugin <= 23.2 - Broken Access Control Vulnerability

Missing Authorization vulnerability in N-Media Frontend File Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Frontend File Manager: from n/a through 23.2.


We have discovered 15 live websites that are affected by CVE-2025-57921.

Run a Free Instant Scan




Affected Software

Product  Nmedia User File Uploader
Category Wordpress Plugins
Vulnerable Domains15 live websites (100% of Nmedia User File Uploader install base)
Vulnerable Versions
  • from 0 through 23.2
Vulnerable Versions Count1 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Sep 22, 2025
  • Updated - Sep 23, 2025

Credits

  • Hiro (Code016Hiro) (Patchstack Alliance) (finder)

Website Distribution by Country

Number of websites using CVE-2025-57921
United States6 websites



Italy2 websites
Russia2 websites
Australia1 websites
Colombia1 websites
Greece1 websites
Netherlands1 websites
Vietnam1 websites

Website Distribution by TLD

Number of websites using CVE-2025-57921
.com5 websites
.it2 websites
.com.au1 websites
.nl1 websites
.org1 websites
.ru1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-57921

Top websites that are affected by CVE-2025-57921. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.org United States*,***,***
*************.com United States*,***,***
*****.ru Russia**,***,***
***********.com United States**,***,***
********.biz Russia**,***,***
****************.com United States**,***,***
*************.nl Netherlands**,***,***
***********.***.vn Vietnam**,***,***
**************.com United States**,***,***
************.com United States**,***,***
See full domain list

FAQ

CVE-2025-57921 is Missing Authorization in Nmedia User File Uploader
A total of 15 websites have been identified as vulnerable to CVE-2025-57921, based on global website indexing conducted by WebTechSurvey.
The Nmedia User File Uploader is affected by the CVE-2025-57921 vulnerability.
Nmedia User File Uploader versions up to and including 23.2 are vulnerable to CVE-2025-57921.