PT-2026-69366 · WordPress · File Manager
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
File Manager WordPress plugin versions prior to 6.9.1
Description
Lack of authorization checks on a REST API route allows unauthenticated users to access the file activity log. This leads to the disclosure of file operations performed on the site, including the involved file paths and the names of the users who executed those operations.
Recommendations
Update the File Manager WordPress plugin to version 6.9.1 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
File Manager