CVE-2026-85081: CWE-79 Cross-Site Scripting (XSS) in File Manager
The File Manager WordPress plugin before 8.0.5, FileOrganizer WordPress plugin before 1.2.1, File Manager Pro WordPress plugin before 2.1.3 do not correctly validate the origin of window messages received by the file browser they load on their admin screens, accepting any origin that is a leading string prefix of the site's own address, which allows an unauthenticated attacker to run arbitrary JavaScript in the session of a logged-in administrator who visits a page under their control. The defect is in the file-manager library all three bundle, and every version below 2.1.70 carries it. Updating the bundled library closes it.
AI Analysis
Technical Summary
CVE-2026-85081 is a Cross-Site Scripting (CWE-79) vulnerability in the File Manager WordPress plugin and related plugins caused by improper origin validation of window messages in the file browser loaded on admin screens. The plugins accept any origin that is a leading string prefix of the site's address, enabling an unauthenticated attacker to execute arbitrary JavaScript in the context of a logged-in administrator's session if they visit a malicious page. This vulnerability affects File Manager versions prior to 8.0.5, FileOrganizer prior to 1.2.1, and File Manager Pro prior to 2.1.3. The root cause is in the shared file-manager library, with all versions below 2.1.70 vulnerable. Remediation involves updating the bundled library to a fixed version.
Potential Impact
An unauthenticated attacker can execute arbitrary JavaScript in the session of a logged-in administrator by exploiting this XSS vulnerability. This can lead to session hijacking, unauthorized actions performed with administrator privileges, or other attacks leveraging the administrator's elevated permissions. The attack requires the administrator to visit a page controlled by the attacker.
Mitigation Recommendations
Update the File Manager plugin to version 8.0.5 or later, FileOrganizer to version 1.2.1 or later, and File Manager Pro to version 2.1.3 or later. These updates include a fixed version of the bundled file-manager library (version 2.1.70 or later) that correctly validates the origin of window messages. Applying these official fixes fully mitigates the vulnerability.
CVE-2026-85081: CWE-79 Cross-Site Scripting (XSS) in File Manager
Description
The File Manager WordPress plugin before 8.0.5, FileOrganizer WordPress plugin before 1.2.1, File Manager Pro WordPress plugin before 2.1.3 do not correctly validate the origin of window messages received by the file browser they load on their admin screens, accepting any origin that is a leading string prefix of the site's own address, which allows an unauthenticated attacker to run arbitrary JavaScript in the session of a logged-in administrator who visits a page under their control. The defect is in the file-manager library all three bundle, and every version below 2.1.70 carries it. Updating the bundled library closes it.
CVSS v3.1
Score 7.5high
Affected software
File Manager
FileOrganizer
File Manager Pro
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-85081 is a Cross-Site Scripting (CWE-79) vulnerability in the File Manager WordPress plugin and related plugins caused by improper origin validation of window messages in the file browser loaded on admin screens. The plugins accept any origin that is a leading string prefix of the site's address, enabling an unauthenticated attacker to execute arbitrary JavaScript in the context of a logged-in administrator's session if they visit a malicious page. This vulnerability affects File Manager versions prior to 8.0.5, FileOrganizer prior to 1.2.1, and File Manager Pro prior to 2.1.3. The root cause is in the shared file-manager library, with all versions below 2.1.70 vulnerable. Remediation involves updating the bundled library to a fixed version.
Potential Impact
An unauthenticated attacker can execute arbitrary JavaScript in the session of a logged-in administrator by exploiting this XSS vulnerability. This can lead to session hijacking, unauthorized actions performed with administrator privileges, or other attacks leveraging the administrator's elevated permissions. The attack requires the administrator to visit a page controlled by the attacker.
Mitigation Recommendations
Update the File Manager plugin to version 8.0.5 or later, FileOrganizer to version 1.2.1 or later, and File Manager Pro to version 2.1.3 or later. These updates include a fixed version of the bundled file-manager library (version 2.1.70 or later) that correctly validates the origin of window messages. Applying these official fixes fully mitigates the vulnerability.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-09-02T21:47:57.788Z
- State
- PUBLISHED
Threat ID: 6ab7672cf7a7c54106f7c891
Added to database: 09/26/2026, 06:33:16 UTC
Last enriched: 09/26/2026, 06:48:05 UTC
Last updated: 09/27/2026, 04:31:14 UTC
Views: 18
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.