The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connector endpoints, allowing any authenticated user, such as a subscriber, to browse the entire WordPress installation directory and download files of certain types from it, including archives and documents which may contain sensitive data.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-10 07:16
Updated : 2026-08-26 16:31
NVD link : CVE-2026-17542
Mitre link : CVE-2026-17542
CVE.ORG link : CVE-2026-17542
JSON object : View
Products Affected
No product.
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
