CVE-2026-17542
7.5WordPress · File Manager
The File Manager WordPress plugin contains an information exposure vulnerability allowing unauthenticated attackers to access sensitive system resources.
Executive summary
The File Manager WordPress plugin is affected by an information exposure vulnerability that enables unauthenticated attackers to access sensitive data, presenting a high risk of compromise.
Vulnerability
This vulnerability is an information exposure (CWE-200) that can be triggered over the network by an unauthenticated attacker. It does not require user interaction to successfully access sensitive information.
Business impact
With a CVSS score of 7.5, this vulnerability poses a high risk to business operations by enabling unauthorized access to potentially sensitive information. Such exposure can lead to the loss of proprietary data, unauthorized configuration changes, or the leakage of sensitive credentials stored within the file system.
Remediation
Immediate Action: Update the File Manager plugin to version 6.9.1 or the latest available version provided by the vendor.
Proactive Monitoring: Monitor logs for unauthorized access attempts or unusual patterns in file retrieval requests that deviate from normal administrative activity.
Compensating Controls: Utilize a Web Application Firewall (WAF) to filter out malicious requests targeting the File Manager plugin functionality.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
Given the high CVSS score and the nature of the vulnerability, it is imperative to update the plugin to version 6.9.1 immediately. Failure to address this flaw could allow unauthorized entities to bypass security controls and access sensitive information on the host server.