CVE-2026-19708
File Manager 7.2.2 - 8.0.4 - Unauthenticated Database Backup Disclosure
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The File Manager WordPress plugin before 8.0.5 does not prevent unauthenticated users from downloading its database backup archives, and in some cases writes them under a fixed filename, allowing unauthenticated attackers to retrieve a full database dump including every user's email address and password hash on servers that do not apply the directory's .htaccess file.
| Vendor | unknown |
| Product | file manager |
| Published | Sep 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown file manager
Be the first to know when new unknown vulnerabilities affecting unknown file manager are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / File Manager
7.2.2 < 8.0.5
References
Credits
Jakub Herman WPScan