๐Ÿ” CVE Alert

CVE-2026-17542

UNKNOWN 0.0

Bit File Manager < 6.9.1 - Subscriber+ Sensitive Data Disclosure via bitapps_fm_connector

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connector endpoints, allowing any authenticated user, such as a subscriber, to browse the entire WordPress installation directory and download files of certain types from it, including archives and documents which may contain sensitive data.

Vendor unknown
Product file manager
Published Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for unknown file manager

Be the first to know when new unknown vulnerabilities affecting unknown file manager are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / File Manager
0 < 6.9.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/d17f3de9-b0f9-4bbd-8a57-18cda9d43d79/

Credits

JING QIAN WPScan