Skip to main content
EPSS 0.2%top 94%

CVE-2026-85081: CWE-79 Cross-Site Scripting (XSS) in File Manager

0
High
Published: 09/26/2026 (09/26/2026, 09:30:19 UTC)
Source: CVE Database V5
Product: File Manager

Description

The File Manager WordPress plugin before 8.0.5, FileOrganizer WordPress plugin before 1.2.1, File Manager Pro WordPress plugin before 2.1.3 do not correctly validate the origin of window messages received by the file browser they load on their admin screens, accepting any origin that is a leading string prefix of the site's own address, which allows an unauthenticated attacker to run arbitrary JavaScript in the session of a logged-in administrator who visits a page under their control. The defect is in the file-manager library all three bundle, and every version below 2.1.70 carries it. Updating the bundled library closes it.

CVSS v3.1

Score 7.5high

Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected software

File Manager

Affected versions
>=0 <8.0.5

FileOrganizer

Affected versions
>=0 <1.2.1

File Manager Pro

Affected versions
>=0 <2.1.3

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/26/2026, 06:48:05 UTC

Technical Analysis

CVE-2026-85081 is a Cross-Site Scripting (CWE-79) vulnerability in the File Manager WordPress plugin and related plugins caused by improper origin validation of window messages in the file browser loaded on admin screens. The plugins accept any origin that is a leading string prefix of the site's address, enabling an unauthenticated attacker to execute arbitrary JavaScript in the context of a logged-in administrator's session if they visit a malicious page. This vulnerability affects File Manager versions prior to 8.0.5, FileOrganizer prior to 1.2.1, and File Manager Pro prior to 2.1.3. The root cause is in the shared file-manager library, with all versions below 2.1.70 vulnerable. Remediation involves updating the bundled library to a fixed version.

Potential Impact

An unauthenticated attacker can execute arbitrary JavaScript in the session of a logged-in administrator by exploiting this XSS vulnerability. This can lead to session hijacking, unauthorized actions performed with administrator privileges, or other attacks leveraging the administrator's elevated permissions. The attack requires the administrator to visit a page controlled by the attacker.

Mitigation Recommendations

Update the File Manager plugin to version 8.0.5 or later, FileOrganizer to version 1.2.1 or later, and File Manager Pro to version 2.1.3 or later. These updates include a fixed version of the bundled file-manager library (version 2.1.70 or later) that correctly validates the origin of window messages. Applying these official fixes fully mitigates the vulnerability.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
WPScan
Date Reserved
2026-09-02T21:47:57.788Z
State
PUBLISHED

Threat ID: 6ab7672cf7a7c54106f7c891

Added to database: 09/26/2026, 06:33:16 UTC

Last enriched: 09/26/2026, 06:48:05 UTC

Last updated: 09/27/2026, 04:31:14 UTC

Views: 18

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses