---
id: CVE-2026-85081
title: >-
  The File Manager WordPress plugin before 8.0.5, FileOrganizer  WordPress
  plugin before 1.2.1, File Manager Pro  WordPress plugin before 2.1.3 do not
  correctly validate the origin of window messages received by the file browser
  they load …
summary: >-
  The File Manager WordPress plugin before 8.0.5, FileOrganizer  WordPress
  plugin before 1.2.1, File Manager Pro  WordPress plugin before 2.1.3 do not
  correctly validate the origin of window messages received by the file browser
  they load …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-79
product: File Manager
affected:
  - file_manager < 8.0.5
  - FileOrganizer < 1.2.1
  - file_manager_pro < 2.1.3
published: '2026-09-26'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T23:16:38.233'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85081'
references:
  - url: 'https://wpscan.com/vulnerability/3c5f9c52-e609-45aa-b441-491e15b3f4b8/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-26T22:33:20.658461Z'
epss: 0.00173
epssPercentile: 0.05991
ingestedAt: '2026-09-26T06:27:03.684Z'
---

## Overview

The File Manager WordPress plugin before 8.0.5, FileOrganizer  WordPress plugin before 1.2.1, File Manager Pro  WordPress plugin before 2.1.3 do not correctly validate the origin of window messages received by the file browser they load on their admin screens, accepting any origin that is a leading string prefix of the site's own address, which allows an unauthenticated attacker to run arbitrary JavaScript in the session of a logged-in administrator who visits a page under their control.

The defect is in the file-manager library all three bundle, and every version below 2.1.70 carries it. Updating the bundled library closes it.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
