File Manager Plugin in WordPress Exposes Sensitive Data to Authenticated Users
CVE-2026-17542
7.5HIGH
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 10 August 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-17542?
The File Manager Plugin for WordPress prior to version 6.9.1 lacks proper capability checks on a critical file management endpoint. This oversight allows any authenticated user, such as a subscriber, to access and navigate the entire WordPress installation directory. Consequently, users can download various file types, including archives and documents that may contain sensitive information, thus posing a significant risk to data security.
Affected Version(s)
File Manager 0 < 6.9.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
JING QIAN
WPScan