CVE-2026-17541

The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to read its file activity log, disclosing the file operations performed on the site, the paths involved and the name of the user who performed them.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-10 07:16

Updated : 2026-08-26 16:31


NVD link : CVE-2026-17541

Mitre link : CVE-2026-17541

CVE.ORG link : CVE-2026-17541


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor