What is CVE-2026-17541?
The File Manager WordPress plugin before version 6.9.1 lacks authorization checks on one of its REST API routes. This allows unauthenticated users to read the file activity log, disclosing performed file operations, their paths, and the associated usernames.
Azərbaycanca: CVE-2026-17541, WordPress-in File Manager plaginində (6.9.1 versiyasından əvvəl) avtorizasiya yoxlamasının olmaması ilə bağlıdır. Bu boşluq autentifikasiya olunmamış istifadəçilərə REST API vasitəsilə fayl əməliyyatları jurnalını oxumağa imkan verir, fayl yollarını və əməliyyatı icra edən istifadəçi adını ifşa edir.
Related CVEs
link basis: same weakness class CWE-862
FAQ1
What type of information does CVE-2026-17541 expose in the File Manager plugin for WordPress?
This vulnerability allows unauthenticated users to read the file activity log via a REST API route. The disclosed information includes performed file operations, their paths, and the associated usernames.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.