CVE-2026-12277 affects the Frontend File Manager Plugin for WordPress through version 23.6. The plugin fails to properly validate or constrain a file path derived from user-controlled input before deleting the referenced file. When the plugin's guest upload mode is enabled, this flaw allows unauthenticated remote attackers to trigger deletion of arbitrary files on the server accessible to the web application. The published description specifically notes deletion of wp-config.php as a practical exploitation target. Removing that file causes WordPress to enter its installation/setup routine again, which can then be leveraged toward full site takeover.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a working exploit set for CVE-2026-12277 affecting the WordPress Frontend File Manager plugin (nmedia-user-file-uploader) <= 23.6. The repo has 6 files: one main Python exploit (exploit.py), two PoC scripts in Bash and PowerShell, a README, a dependency file, and a target list. The main capability is unauthenticated arbitrary file deletion through the plugin’s AJAX metadata update action (wpfm_file_meta_update) combined with the delete action (wpfm_delete_file). The exploit first detects the plugin, extracts the frontend nonce from common WordPress pages, uploads a guest file or brute-forces a valid file_id, overwrites the wpfm_dir_path metadata to an attacker-chosen absolute path such as wp-config.php, and then triggers deletion. For full compromise, it abuses the resulting WordPress setup state to recreate configuration with attacker-controlled DB credentials, establish admin access, and optionally deploy a PHP command webshell. The Python script is the primary entry point and appears more automated than the shell/PowerShell PoCs, including proxy support, timeout handling, plugin detection, nonce extraction, and takeover logic. This is a real exploit rather than a detector-only script, and its payloading is basic/hardcoded rather than framework-driven.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.