AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-17540

HIGH · CVSS 8.8 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The File Manager plugin for WordPress versions prior to 6.9.1 is vulnerable due to inadequate authorization in its file management commands, enabling any authenticated user, including subscribers, to read and delete arbitrary files within the WordPress installation directory. This flaw poses a risk of exposing sensitive site configuration information and could lead to denial of service. WordPress site administrators and users of the affected plugin should prioritize updating to the latest version to mitigate these risks.

CVE
CVE-2026-17540
Severity
HIGH
CVSS
8.8
EPSS
0.29%
WordPress

Original NVD Description

The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a subscriber, to read and delete arbitrary files under the WordPress installation directory, which could lead to the disclosure of the site's configuration secrets and to denial of service.