cleantalk
Vulnerabilities and Security Researches

File Manager, CVE-2026-19708

CVE, Research URL

CVE-2026-19708

Application

File Manager

Published on
Sep 26, 2026
Research Description
The File Manager WordPress plugin before 8.0.5 does not prevent unauthenticated users from downloading its database backup archives, and in some cases writes them under a fixed filename, allowing unauthenticated attackers to retrieve a full database dump including every user's email address and password hash on servers that do not apply the directory's .htaccess file.
Affected versions
Min 7.2.2, max 8.0.5.
Status
vulnerable