File Manager Plugin in WordPress Exposes Sensitive Data to Authenticated Users
CVE-2026-17542
Currently unrated
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 10 August 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-17542?
The File Manager Plugin for WordPress prior to version 6.9.1 lacks proper capability checks on a critical file management endpoint. This oversight allows any authenticated user, such as a subscriber, to access and navigate the entire WordPress installation directory. Consequently, users can download various file types, including archives and documents that may contain sensitive information, thus posing a significant risk to data security.
Affected Version(s)
File Manager 0 < 6.9.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.