The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a subscriber, to read and delete arbitrary files under the WordPress installation directory, which could lead to the disclosure of the site's configuration secrets and to denial of service.
History

Tue, 11 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Filemanagerpro
Filemanagerpro file Manager
Wordpress
Wordpress wordpress
Vendors & Products Filemanagerpro
Filemanagerpro file Manager
Wordpress
Wordpress wordpress

Mon, 10 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Mon, 10 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a subscriber, to read and delete arbitrary files under the WordPress installation directory, which could lead to the disclosure of the site's configuration secrets and to denial of service.
Title Bit File Manager < 6.9.1 - Subscriber+ Arbitrary File Read and Deletion via Connector Command Request-Source Mismatch
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2026-08-10T06:00:10.472Z

Updated: 2026-08-11T20:10:28.739Z

Reserved: 2026-07-27T10:00:16.040Z

Link: CVE-2026-17540

cve-icon Vulnrichment

Updated: 2026-08-11T20:10:20.543Z

cve-icon NVD

Status : Received

Published: 2026-08-10T07:16:49.460

Modified: 2026-08-11T21:17:30.100

Link: CVE-2026-17540

cve-icon Redhat

No data.