CVE-2026-19708
Received Received - Intake

Unauthenticated Database Backup Download in File Manager WordPress Plugin

Vulnerability report for CVE-2026-19708, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-26

Last updated on: 2026-09-26

Assigner: WPScan

Description

The File Manager WordPress plugin before 8.0.5 does not prevent unauthenticated users from downloading its database backup archives, and in some cases writes them under a fixed filename, allowing unauthenticated attackers to retrieve a full database dump including every user's email address and password hash on servers that do not apply the directory's .htaccess file.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-26
Last Modified
2026-09-26
Generated
2026-09-26
AI Q&A
2026-09-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wpmedia file_manager 7.2.2
wpmedia file_manager to 8.0.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The File Manager WordPress plugin before version 8.0.5 has a vulnerability where unauthenticated users can download database backup archives. In some cases, these backups are saved with fixed filenames, making them easily accessible. Attackers can exploit this to retrieve a full database dump containing sensitive user data like email addresses and password hashes, especially if the server's directory .htaccess file is not enforced.

Detection Guidance

Check if the File Manager plugin version is between 7.2.2 and 8.0.4. Look for database backup files in the plugin's directory, especially with fixed filenames. Verify if .htaccess is properly enforced in the directory to prevent unauthorized access.

Impact Analysis

This vulnerability allows attackers to access your WordPress site's full database, including all user emails and password hashes. If your server lacks proper .htaccess enforcement, attackers can download these backups without authentication. This could lead to data breaches, unauthorized access to user accounts, and potential misuse of personal information.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA due to unauthorized access to sensitive personal data. GDPR requires protection of personal data, and HIPAA mandates safeguards for protected health information. A breach could result in legal penalties, fines, and reputational damage for organizations handling regulated data.

Mitigation Strategies

Update the File Manager plugin to version 8.0.5 or later immediately. Ensure the .htaccess file is enforced in the plugin's directory to restrict access. Remove any exposed database backup files from the server.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19708. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart