CVE-2026-17540
Bit File Manager < 6.9.1 - Subscriber+ Arbitrary File Read and Deletion via Connector Command Request-Source Mismatch
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a subscriber, to read and delete arbitrary files under the WordPress installation directory, which could lead to the disclosure of the site's configuration secrets and to denial of service.
| Vendor | unknown |
| Product | file manager |
| Published | Aug 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown file manager
Be the first to know when new unknown vulnerabilities affecting unknown file manager are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / File Manager
0 < 6.9.1
References
Credits
Artus KG WPScan