CVE-2026-17542 PUBLISHED

Bit File Manager < 6.9.1 - Subscriber+ Sensitive Data Disclosure via bitapps_fm_connector

Assigner: WPScan
Reserved: 27.07.2026 Published: 10.08.2026 Updated: 10.08.2026

The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connector endpoints, allowing any authenticated user, such as a subscriber, to browse the entire WordPress installation directory and download files of certain types from it, including archives and documents which may contain sensitive data.

Product Status

Vendor Unknown
Product File Manager
Versions Default: unaffected
  • affected from 0 to 6.9.1 (excl.)

Credits

  • JING QIAN finder
  • WPScan coordinator

References

Problem Types

  • CWE-200 Information Exposure CWE