The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to read its file activity log, disclosing the file operations performed on the site, the paths involved and the name of the user who performed them.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-10 07:16
Updated : 2026-08-26 16:31
NVD link : CVE-2026-17541
Mitre link : CVE-2026-17541
CVE.ORG link : CVE-2026-17541
JSON object : View
Products Affected
No product.
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
