What is CVE-2026-17542?
CVE-2026-17542 is a vulnerability in the File Manager WordPress plugin before version 6.9.1, caused by a missing capability check on a file manager connector endpoint. This allows any authenticated user, such as a subscriber, to browse the entire WordPress installation directory and download specific file types from it. Upgrade to version 6.9.1 or later is required.
Azərbaycanca: CVE-2026-17542, 6.9.1 versiyasından əvvəlki File Manager WordPress pluginində identifikasiya edilmiş bir zəiflikdir. Bu zəiflik, 'file manager connector' endpointində hər hansı bir icazə yoxlaması aparılmaması səbəbindən, abunəçi kimi autentifikasiya olunmuş istənilən istifadəçiyə WordPress quraşdırma qovluğunda gəzib müəyyən fayl tiplərini yükləməyə imkan verir. Plugin 6.9.1 və ya daha yuxarı versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the File Manager plugin are affected by CVE-2026-17542?
This vulnerability affects all versions of the File Manager plugin before version 6.9.1.
How can a user with a subscriber role exploit CVE-2026-17542?
An authenticated user, such as a subscriber, can browse the WordPress installation directory and download specific file types through the file manager connector endpoint due to a missing capability check.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.