What is CVE-2026-15991?
CVE-2026-15991 is an arbitrary file deletion vulnerability in the File Manager plugin for WordPress (versions 6.0-6.9) caused by insufficient file path validation in the connector function. This allows authenticated attackers with subscriber-level access and above to read and delete arbitrary files on the server. Updating the plugin to the latest version is recommended.
Azərbaycanca: CVE-2026-15991, WordPress üçün File Manager plaginində (6.0-6.9 versiyaları) 'connector' funksiyasındakı kifayət qədər fayl yolu yoxlanışı səbəbindən ixtiyari fayl silmə zəifliyidir. Bu, subcriber və yuxarı giriş səviyyəsinə malik autentifikasiya olunmuş hücumçulara serverdəki ixtiyari faylları oxuyub silməyə imkan verir. Plaginin ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which plugin does CVE-2026-15991 affect and through which function is it exploited?
The vulnerability affects the File Manager plugin for WordPress and is exploited through insufficient file path validation in the 'connector' function.
What is the minimum access level required for an attacker to exploit CVE-2026-15991?
The attacker must be an authenticated user with subscriber-level access and above.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.