plugin

File Manager Vulnerabilities

27 known security issues reported for the File Manager WordPress plugin. Most recent disclosed Aug 5, 2026.

8 high 5 medium 1 low

Running File Manager on your site? Check whether your installed version is affected.

Scan your site free

File Manager 6.0 - 6.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read and Deletion via 'cmd' Query Parameter

high

The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to read and delete arbitrary files on the server,...

CVSS:
8.8
Affected:
6.0 – 6.9
Fixed in:
6.9.1
Disclosed:
Aug 5, 2026

CVE-2026-15991 on NVD →

Bit File Manager <= 6.9.0 - Authenticated (Subscriber+) Arbitrary File Read

medium

The Bit File Manager plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 6.9.0. This is due to insufficient validation of a user supplied path. This makes it possible for authenticated attackers, with subscriber-level access and above, to read arbitrary files on the server, inclu...

CVSS:
6.5
Affected:
up to 6.9.0
Fixed in:
6.9.1
Disclosed:
Aug 4, 2026

CVE-2026-17540 on NVD →

Bit File Manager <= 6.9.0 - Unauthenticated File Activity Log Disclosure

medium

The Bit File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 6.9.0. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 6.9.0
Fixed in:
6.9.1
Disclosed:
Aug 4, 2026

CVE-2026-17541 on NVD →

Bit File Manager <= 6.9.0 - Authenticated (Subscriber+) Information Exposure

medium

The Bit File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 6.9.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive user or configuration data.

CVSS:
4.3
Affected:
up to 6.9.0
Fixed in:
6.9.1
Disclosed:
Aug 4, 2026

CVE-2026-17542 on NVD →

Multiple Plugins <= Multiple Versions - Authenticated Remote Code Execution

high

Multiple plugins and/or themes for WordPress are vulnerable to Remote Code Execution in various versions. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute code on the server.

CVSS:
7.2
Affected:
up to 8.0.4
Fixed in:
8.0.4
Disclosed:
Jun 15, 2026

CVE-2026-6382 on NVD →

Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress <= 6.7 - Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File Uploads

medium

The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated...

CVSS:
6.4
Affected:
up to 6.7
Fixed in:
6.8
Disclosed:
Jun 2, 2025

CVE-2025-1725 on NVD →

Bit File Manager – 100% Free &amp; Open Source File Manager and Code Editor for WordPress [file-manager] < 6.5.8

unknown

[en] The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and including, 6.5.7. This is due to a lack of proper checks on allowed file types. This makes it possible for authenticated attacker...

Affected:
up to 6.5.8
Fixed in:
6.5.8
Disclosed:
Oct 5, 2024

CVE-2024-8743 on NVD →

Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress <= 6.5.7 - Authenticated (Subscriber+) Limited JavaScript File Upload

medium

The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and including, 6.5.7. This is due to a lack of proper checks on allowed file types. This makes it possible for authenticated attackers, wi...

CVSS:
6.8
Affected:
up to 6.5.7
Fixed in:
6.5.8
Disclosed:
Oct 4, 2024

CVE-2024-8743 on NVD →

Bit File Manager – 100% Free &amp; Open Source File Manager and Code Editor for WordPress [file-manager] < 6.5.6

unknown

[en] The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload' function in all versions up to, and including, 6.5.5. This makes it possible for authenticated attackers, with S...

Affected:
up to 6.5.6
Fixed in:
6.5.6
Disclosed:
Sep 10, 2024

CVE-2024-7770 on NVD →

Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress <= 6.5.5 - Authenticated (Subscriber+) Arbitrary File Upload

high

The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload' function in all versions up to, and including, 6.5.5. This makes it possible for authenticated attackers, with Subscr...

CVSS:
8.8
Affected:
up to 6.5.5
Fixed in:
6.5.6
Disclosed:
Sep 9, 2024

CVE-2024-7770 on NVD →

Bit File Manager – 100% Free &amp; Open Source File Manager and Code Editor for WordPress [file-manager] >= 6.0 - <= 6.5.5

unknown

[en] The Bit File Manager plugin for WordPress is vulnerable to Remote Code Execution in versions 6.0 to 6.5.5 via the 'checkSyntax' function. This is due to writing a temporary file to a publicly accessible directory before performing file validation. This makes it possible for unauthenticated attackers to execute cod...

Affected:
6.0 – 6.5.5
Fixed in:
6.5.5
Disclosed:
Sep 5, 2024

CVE-2024-7627 on NVD →

Bit File Manager 6.0 - 6.5.5 - Unauthenticated Remote Code Execution via Race Condition

high

The Bit File Manager plugin for WordPress is vulnerable to Remote Code Execution in versions 6.0 to 6.5.5 via the 'checkSyntax' function. This is due to writing a temporary file to a publicly accessible directory before performing file validation. This makes it possible for unauthenticated attackers to execute code on...

CVSS:
8.1
Affected:
6.0 – 6.5.5
Fixed in:
6.5.6
Disclosed:
Sep 4, 2024

CVE-2024-7627 on NVD →

Bit File Manager – 100% Free &amp; Open Source File Manager and Code Editor for WordPress [file-manager] < 6.0

unknown

[en] Deserialization of Untrusted Data vulnerability in File Manager by Bit Form Team File Manager – 100% Free & Open Source File Manager Plugin for WordPress | Bit File Manager.This issue affects File Manager – 100% Free & Open Source File Manager Plugin for WordPress | Bit File Manager: from n/a through 5.2.7.

Affected:
up to 6.0
Fixed in:
6.0
Disclosed:
Dec 20, 2023

CVE-2022-47599 on NVD →

Bit File Manager – 100% Free &amp; Open Source File Manager and Code Editor for WordPress [file-manager] < 6.3

unknown

[en] The File Manager WordPress plugin before 6.3 does not restrict the file managers root directory, allowing an administrator to set a root outside of the WordPress root directory, giving access to system files and directories even in a multisite setup, where site administrators should not be allowed to modify the si...

Affected:
up to 6.3
Fixed in:
6.3
Disclosed:
Dec 11, 2023

CVE-2023-5907 on NVD →

File Manager <= 6.3 - Authenticated (Admin+) Arbitrary OS File Access via Path Traversal

low

The File Manager – 100% Free & Open Source File Manager Plugin for WordPress | Bit File Manager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.2 via the Root Folder Path setting. This makes it possible for authenticated attackers, with administrative-level access and above,...

CVSS:
2.2
Affected:
up to 6.2
Fixed in:
6.3
Disclosed:
Nov 20, 2023

CVE-2023-5907 on NVD →

Bit File Manager <= 5.2.7 - Authenticated (Admin+) PHP Object Injection

high

The Bit File Manager plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.2.7 via deserialization of untrusted input from the 'language' setting parameter. This allows authenticated attackers, with administrative privileges and above, to inject a PHP Object. No POP chain is pre...

CVSS:
7.2
Affected:
up to 5.2.7
Fixed in:
6.0
Disclosed:
Apr 28, 2023

CVE-2022-47599 on NVD →

Bit File Manager – 100% Free &amp; Open Source File Manager and Code Editor for WordPress [file-manager] < 5.2.3

unknown

[en] The Library File Manager WordPress plugin before 5.2.3 is using an outdated version of the elFinder library, which is know to be affected by security issues (CVE-2021-32682), and does not have any authorisation as well as CSRF checks in its connector AJAX action, allowing any authenticated users, such as subscribe...

Affected:
up to 5.2.3
Fixed in:
5.2.3
Disclosed:
Apr 4, 2022

CVE-2022-0403 on NVD →

Bit File Manager – 100% Free &amp; Open Source File Manager and Code Editor for WordPress [file-manager] < 5.2.3

unknown

Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress Library File Manager plugin (versions <= 5.2.2).

Affected:
up to 5.2.3
Fixed in:
5.2.3
Disclosed:
Mar 30, 2022

Bit File Manager – 100% free file manager for WordPress <= 5.2.2 - Subscriber+ Arbitrary File Creation/Upload/Deletion

high

The Library File Manager WordPress plugin before 5.2.3 is using an outdated version of the elFinder library, which is known to be affected by security issues (CVE-2021-32682), and does not have any authorisation as well as CSRF checks in its connector AJAX action, allowing any authenticated users, such as subscriber to...

CVSS:
8.8
Affected:
up to 5.2.2
Fixed in:
5.2.3
Disclosed:
Mar 14, 2022

CVE-2022-0403 on NVD →

Bit File Manager – 100% Free &amp; Open Source File Manager and Code Editor for WordPress [file-manager] < 5.2.3

unknown

[en] elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerabilities can allow an attacker to execute arbitrary code and commands on the server hosting the elFinder PHP connector, even with minimal configuration. The issues we...

Affected:
up to 5.2.3
Fixed in:
5.2.3
Disclosed:
Jun 14, 2021

CVE-2021-32682 on NVD →

Bit File Manager – 100% Free &amp; Open Source File Manager and Code Editor for WordPress [file-manager] < 4.9

unknown

Multiple Vulnerabilities found by WebARX in WordPress File Manager plugin (versions <= 4.8).

Affected:
up to 4.9
Fixed in:
4.9
Disclosed:
Jul 10, 2019

Bit File Manager – 100% Free &amp; Open Source File Manager and Code Editor for WordPress [file-manager] < 5.0.2

unknown

[en] inc/logger.php in the Giribaz File Manager plugin before 5.0.2 for WordPress logged activity related to the plugin in /wp-content/uploads/file-manager/log.txt. If a user edits the wp-config.php file using this plugin, the wp-config.php contents get added to log.txt, which is not protected and contains database cre...

Affected:
up to 5.0.2
Fixed in:
5.0.2
Disclosed:
Mar 7, 2018

CVE-2018-7204 on NVD →

Bit File Manager <= 5.0.0 - Information Disclosure

high

inc/logger.php in the Giribaz File Manager plugin before 5.0.2 for WordPress logged activity related to the plugin in /wp-content/uploads/file-manager/log.txt. If a user edits the wp-config.php file using this plugin, the wp-config.php contents get added to log.txt, which is not protected and contains database credenti...

CVSS:
7.5
Affected:
up to 5.0.0
Fixed in:
5.0.2
Disclosed:
Mar 2, 2018

CVE-2018-7204 on NVD →

Bit File Manager <= 4.1.4 - Cross-Site Request Forgery to Arbitrary File Upload

high

The Bit File Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.4. This is due to missing or incorrect nonce validation on the plugin's upload form. This makes it possible for unauthenticated attackers to upload arbitrary files to the server via a forged reque...

CVSS:
8.8
Affected:
up to 4.1.5
Fixed in:
4.1.5
Disclosed:
Mar 1, 2017

Bit File Manager – 100% Free &amp; Open Source File Manager and Code Editor for WordPress [file-manager] < 4.1.5

unknown

The Bit File Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.4. This is due to missing or incorrect nonce validation on the plugin's upload form. This makes it possible for unauthenticated attackers to upload arbitrary files to the server via a forged reque...

Affected:
up to 4.1.5
Fixed in:
4.1.5
Disclosed:
Mar 1, 2017

Bit File Manager – 100% Free &amp; Open Source File Manager and Code Editor for WordPress [file-manager] < 4.1.5

unknown

The File Manager WordPress plugin was affected by a Cross-Site Request Forgery (CSRF) Arbitrary File Upload security vulnerability.

Affected:
up to 4.1.5
Fixed in:
4.1.5

Bit File Manager – 100% Free &amp; Open Source File Manager and Code Editor for WordPress [file-manager] < 6.8

unknown
Affected:
up to 6.8
Fixed in:
6.8

CVE-2025-1725 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database