CVE-2026-85081
Received Received - Intake

Cross-Site Scripting in File Manager WordPress Plugins

Vulnerability report for CVE-2026-85081, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-26

Last updated on: 2026-09-26

Assigner: WPScan

Description

The File Manager WordPress plugin before 8.0.5, FileOrganizer WordPress plugin before 1.2.1, File Manager Pro WordPress plugin before 2.1.3 do not correctly validate the origin of window messages received by the file browser they load on their admin screens, accepting any origin that is a leading string prefix of the site's own address, which allows an unauthenticated attacker to run arbitrary JavaScript in the session of a logged-in administrator who visits a page under their control. The defect is in the file-manager library all three bundle, and every version below 2.1.70 carries it. Updating the bundled library closes it.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-26
Last Modified
2026-09-26
Generated
2026-09-26
AI Q&A
2026-09-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wp-media wp-file-manager to 8.0.5 (exc)
fileorganizer fileorganizer to 1.2.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-85081 is a DOM-based Cross-Site Scripting (XSS) vulnerability affecting multiple WordPress plugins. It occurs because the plugins fail to properly validate the origin of window messages received by the file browser on their admin screens. They accept any origin that is a leading string prefix of the site's own address, allowing unauthenticated attackers to execute arbitrary JavaScript in the session of a logged-in administrator.

Detection Guidance

This vulnerability is specific to WordPress plugins and cannot be detected via standard network or system commands. Check if you are running vulnerable versions of the affected plugins: wp-file-manager before 8.0.5, fileorganizer before 1.2.1, or filester before 2.1.3. Review plugin update logs or admin dashboards for these plugins.

Impact Analysis

An attacker could trick an administrator into visiting a malicious page, which would then execute arbitrary JavaScript in the administrator's session. This could lead to unauthorized actions being performed on the website, such as creating new admin accounts, modifying content, or stealing sensitive data.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, which may violate compliance requirements under GDPR, HIPAA, or other regulations. For example, GDPR requires protecting personal data, and a breach could result in legal penalties. HIPAA mandates safeguarding protected health information, and this flaw could expose such data.

Mitigation Strategies

Update the affected plugins immediately to the latest patched versions: wp-file-manager to 8.0.5, fileorganizer to 1.2.1, or filester to 2.1.3. Ensure the bundled file-manager library is updated to version 2.1.70 or higher. Remove or disable any unused plugins to reduce attack surface.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85081. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart