CVE-2026-17542
Received Received - Intake

Authenticated File Access in WordPress File Manager Plugin

Vulnerability report for CVE-2026-17542, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: WPScan

Description

The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connector endpoints, allowing any authenticated user, such as a subscriber, to browse the entire WordPress installation directory and download files of certain types from it, including archives and documents which may contain sensitive data.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-10
AI Q&A
2026-08-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wp_media file_manager to 6.9.1 (exc)
bit_file_manager bit_file_manager to 6.9.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the File Manager WordPress plugin before version 6.9.1 allows any authenticated user, including low-privilege users like subscribers, to browse the entire WordPress installation directory and download certain file types such as archives and documents that may contain sensitive data. The issue occurs because the plugin fails to perform capability checks on one of its file manager connector endpoints.

Detection Guidance

Check if the File Manager WordPress plugin version is below 6.9.1. Log in as a subscriber or low-privilege user and attempt to access the vulnerable endpoint to browse directories or download files. Use tools like WPScan to scan for vulnerable plugins.

Impact Analysis

An attacker with authenticated access could exploit this to access sensitive files on your WordPress site, potentially leading to data breaches, unauthorized information disclosure, or further exploitation of your system. This includes downloading archives or documents that may contain confidential or proprietary information.

Compliance Impact

This vulnerability could lead to non-compliance with data protection regulations such as GDPR or HIPAA by exposing sensitive personal or health information. Organizations may face legal penalties, fines, or reputational damage if such data is compromised due to inadequate security controls.

Mitigation Strategies

Update the File Manager plugin to version 6.9.1 or later immediately. If updating is not possible, consider disabling the plugin until a patch is applied. Review file permissions and sensitive data exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-17542. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart