CVE-2026-17542
Bit File Manager < 6.9.1 - Subscriber+ Sensitive Data Disclosure via bitapps_fm_connector
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connector endpoints, allowing any authenticated user, such as a subscriber, to browse the entire WordPress installation directory and download files of certain types from it, including archives and documents which may contain sensitive data.
| Vendor | unknown |
| Product | file manager |
| Published | Aug 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown file manager
Be the first to know when new unknown vulnerabilities affecting unknown file manager are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / File Manager
0 < 6.9.1
References
Credits
JING QIAN WPScan