rootpwn

high · CVSS v3 7.5 · EPSS 0.00145

CVE-2026-19708

The File Manager WordPress plugin before 8.0.5 does not prevent unauthenticated users from downloading its database back…

Description

The File Manager WordPress plugin before 8.0.5 does not prevent unauthenticated users from downloading its database backup archives, and in some cases writes them under a fixed filename, allowing unauthenticated attackers to retrieve a full database dump including every user's email address and password hash on servers that do not apply the directory's .htaccess file.

Scores

Severity
high
CVSS v2
5
CVSS v3
7.5
CVSS v4
—
EPSS
0.00145

← All CVEs