WordPress · File Manager · CVE-2026-17542
**Name of the Vulnerable Software and Affected Versions**
File Manager versions prior to 6.9.1
**Description**
An issue exists where a capability check is missing on the `bitapps fm connector` endpoint. This allows any authenticated user, including those with subscriber-level privileges, to browse the entire WordPress installation directory and download specific file types, such as archives and documents, which may contain sensitive data.
**Recommendations**
Update to version 6.9.1 or later.
Restrict access to the `bitapps fm connector` endpoint as a temporary mitigation measure.