CVE-2026-1280

Frontend File Manager Plugin <= 23.5 - Missing Authorization to Unauthenticated Arbitrary File Sharing via 'file_id' Parameter

The Frontend File Manager Plugin for WordPress is vulnerable to unauthorized file sharing due to a missing capability check on the 'wpfm_send_file_in_email' AJAX action in all versions up to, and including, 23.5. This makes it possible for unauthenticated attackers to share arbitrary uploaded files via email by supplying a file ID. Since file IDs are sequential integers, attackers can enumerate all uploaded files on the site and exfiltrate sensitive data that was intended to be restricted to administrators only.


We have discovered 15 live websites that are affected by CVE-2026-1280.

Run a Free Instant Scan




Affected Software

Product  Nmedia User File Uploader
Category Wordpress Plugins
Vulnerable Domains15 live websites (100% of Nmedia User File Uploader install base)
Vulnerable Versions
  • from 0 through 23.5
Vulnerable Versions Count1 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Jan 28, 2026
  • Updated - Jan 28, 2026

Credits

  • Md. Moniruzzaman Prodhan (finder)

Website Distribution by Country

Number of websites using CVE-2026-1280
United States6 websites



Italy2 websites
Russia2 websites
Australia1 websites
Colombia1 websites
Greece1 websites
Netherlands1 websites
Vietnam1 websites

Website Distribution by TLD

Number of websites using CVE-2026-1280
.com5 websites
.it2 websites
.com.au1 websites
.nl1 websites
.org1 websites
.ru1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-1280

Top websites that are affected by CVE-2026-1280. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.org United States*,***,***
*************.com United States*,***,***
*****.ru Russia**,***,***
***********.com United States**,***,***
********.biz Russia**,***,***
****************.com United States**,***,***
*************.nl Netherlands**,***,***
***********.***.vn Vietnam**,***,***
**************.com United States**,***,***
************.com United States**,***,***
See full domain list

FAQ

CVE-2026-1280 is Missing Authorization in Nmedia User File Uploader
A total of 15 websites have been identified as vulnerable to CVE-2026-1280, based on global website indexing conducted by WebTechSurvey.
The Nmedia User File Uploader is affected by the CVE-2026-1280 vulnerability.
Nmedia User File Uploader versions up to and including 23.5 are vulnerable to CVE-2026-1280.