The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to read its file activity log, disclosing the file operations performed on the site, the paths involved and the name of the user who performed them.
Metrics
Affected Vendors & Products
References
History
Mon, 10 Aug 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to read its file activity log, disclosing the file operations performed on the site, the paths involved and the name of the user who performed them. | |
| Title | Bit File Manager < 6.9.1 - Unauthenticated File Activity Log Disclosure | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-10T06:00:10.691Z
Reserved: 2026-07-27T10:00:18.731Z
Link: CVE-2026-17541
No data.
No data.
No data.
OpenCVE Enrichment
No data.