CyberRota Analysis
AI-GeneratedThe File Manager plugin for WordPress versions prior to 6.9.1 is vulnerable due to inadequate authorization in its file management commands, enabling any authenticated user, including subscribers, to read and delete arbitrary files within the WordPress installation directory. This flaw poses a risk of exposing sensitive site configuration information and could lead to denial of service. WordPress site administrators and users of the affected plugin should prioritize updating to the latest version to mitigate these risks.
Original NVD Description
The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a subscriber, to read and delete arbitrary files under the WordPress installation directory, which could lead to the disclosure of the site's configuration secrets and to denial of service.