Description
The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a subscriber, to read and delete arbitrary files under the WordPress installation directory, which could lead to the disclosure of the site's configuration secrets and to denial of service.
Published: 2026-08-10
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The File Manager WordPress plugin prior to version 6.9.1 allows any authenticated user, including those with a subscriber role, to read and delete arbitrary files located anywhere under the WordPress installation directory. This improper authorization flaw can lead to the exposure of sensitive configuration data and the removal of critical files, potentially causing a denial‑of‑service condition for the site. The weakness aligns with Improper Authorization (CWE‑284).

Affected Systems

WordPress sites using the File Manager plugin version 6.9.0 or earlier are affected. The vulnerability is present in all releases of the plugin before 6.9.1, regardless of WordPress version or theme used.

Risk and Exploitability

The risk is substantial because the attacker only needs to be an authenticated user, which is often the case for standard subscribers. The CVSS score of 8.8 indicates high severity. The EPSS score of <1% suggests exploitation probability is low, but the vulnerability is still not listed in CISA’s KEV catalog. The attack vector is inferred to be via normal authenticated access to the plugin’s endpoint, exploiting the request source mismatch that bypasses role checks.

Generated by OpenCVE AI on August 13, 2026 at 11:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the File Manager plugin to version 6.9.1 or later to remove the authorization flaw.
  • If an upgrade cannot be performed immediately, restrict access to the plugin’s file‑management features to administrators only, either by changing the plugin’s role‑based settings or using a role‑management plugin.
  • Revoke or delete any subscriber accounts that currently have access to the File Manager, ensuring only trusted users retain the capability.
  • As a temporary hardening step, check the file permissions of the WordPress installation directory and set them to restrict non‑admin users from reading or deleting files (e.g., using 640 permissions or appropriate .htaccess rules).

Generated by OpenCVE AI on August 13, 2026 at 11:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Tue, 11 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Filemanagerpro
Filemanagerpro file Manager
Wordpress
Wordpress wordpress
Vendors & Products Filemanagerpro
Filemanagerpro file Manager
Wordpress
Wordpress wordpress

Mon, 10 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Mon, 10 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a subscriber, to read and delete arbitrary files under the WordPress installation directory, which could lead to the disclosure of the site's configuration secrets and to denial of service.
Title Bit File Manager < 6.9.1 - Subscriber+ Arbitrary File Read and Deletion via Connector Command Request-Source Mismatch
References

Subscriptions

Filemanagerpro File Manager
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-11T20:10:28.739Z

Reserved: 2026-07-27T10:00:16.040Z

Link: CVE-2026-17540

cve-icon Vulnrichment

Updated: 2026-08-11T20:10:20.543Z

cve-icon NVD

Status : Deferred

Published: 2026-08-10T07:16:49.460

Modified: 2026-08-26T16:31:16.753

Link: CVE-2026-17540

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T11:45:03Z

Weaknesses