CVE-2026-19708 PUBLISHED

File Manager 7.2.2 - 8.0.4 - Unauthenticated Database Backup Disclosure

Assigner: WPScan
Reserved: 13.08.2026 Published: 26.09.2026 Updated: 26.09.2026

The File Manager WordPress plugin before 8.0.5 does not prevent unauthenticated users from downloading its database backup archives, and in some cases writes them under a fixed filename, allowing unauthenticated attackers to retrieve a full database dump including every user's email address and password hash on servers that do not apply the directory's .htaccess file.

Product Status

Vendor Unknown
Product File Manager
Versions Default: unaffected
  • affected from 7.2.2 to 8.0.5 (excl.)

Credits

  • Jakub Herman finder
  • WPScan coordinator

References

Problem Types

  • CWE-200 Information Exposure CWE