Cross-Site Scripting in File Manager and FileOrganizer WordPress Plugins
CVE-2026-85081
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 26 September 2026
Badges
What is CVE-2026-85081?
The File Manager and FileOrganizer plugins for WordPress feature a vulnerability that fails to validate the origin of window messages on their admin screens. This oversight permits unauthenticated attackers to execute arbitrary JavaScript within the context of a logged-in administrator's session, potentially compromising sensitive information and site integrity. Users of the affected versions are strongly advised to update to secure releases, as the flaw resides in the underlying file-manager library utilized by all three plugins, with versions below 2.1.70 being at risk.
Affected Version(s)
File Manager 0 < 8.0.5
File Manager Pro 0 < 2.1.3
FileOrganizer 0 < 1.2.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.