File Manager 6.0 - 6.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read and Deletion via 'cmd' Query Parameter
high
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to read and delete arbitrary files on the server,...
- CVSS:
- 8.8
- Affected:
- 6.0 – 6.9
- Fixed in:
- 6.9.1
- Disclosed:
- Aug 5, 2026
CVE-2026-15991 on NVD →
Bit File Manager <= 6.9.0 - Authenticated (Subscriber+) Arbitrary File Read
medium
The Bit File Manager plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 6.9.0. This is due to insufficient validation of a user supplied path. This makes it possible for authenticated attackers, with subscriber-level access and above, to read arbitrary files on the server, inclu...
- CVSS:
- 6.5
- Affected:
- up to 6.9.0
- Fixed in:
- 6.9.1
- Disclosed:
- Aug 4, 2026
CVE-2026-17540 on NVD →
Bit File Manager <= 6.9.0 - Unauthenticated File Activity Log Disclosure
medium
The Bit File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 6.9.0. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 6.9.0
- Fixed in:
- 6.9.1
- Disclosed:
- Aug 4, 2026
CVE-2026-17541 on NVD →
Bit File Manager <= 6.9.0 - Authenticated (Subscriber+) Information Exposure
medium
The Bit File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 6.9.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive user or configuration data.
- CVSS:
- 4.3
- Affected:
- up to 6.9.0
- Fixed in:
- 6.9.1
- Disclosed:
- Aug 4, 2026
CVE-2026-17542 on NVD →
Multiple Plugins <= Multiple Versions - Authenticated Remote Code Execution
high
Multiple plugins and/or themes for WordPress are vulnerable to Remote Code Execution in various versions. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute code on the server.
- CVSS:
- 7.2
- Affected:
- up to 8.0.4
- Fixed in:
- 8.0.4
- Disclosed:
- Jun 15, 2026
CVE-2026-6382 on NVD →
Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress <= 6.7 - Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File Uploads
medium
The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated...
- CVSS:
- 6.4
- Affected:
- up to 6.7
- Fixed in:
- 6.8
- Disclosed:
- Jun 2, 2025
CVE-2025-1725 on NVD →
Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress [file-manager] < 6.5.8
unknown
[en] The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and including, 6.5.7. This is due to a lack of proper checks on allowed file types. This makes it possible for authenticated attacker...
- Affected:
- up to 6.5.8
- Fixed in:
- 6.5.8
- Disclosed:
- Oct 5, 2024
CVE-2024-8743 on NVD →
Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress <= 6.5.7 - Authenticated (Subscriber+) Limited JavaScript File Upload
medium
The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and including, 6.5.7. This is due to a lack of proper checks on allowed file types. This makes it possible for authenticated attackers, wi...
- CVSS:
- 6.8
- Affected:
- up to 6.5.7
- Fixed in:
- 6.5.8
- Disclosed:
- Oct 4, 2024
CVE-2024-8743 on NVD →
Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress [file-manager] < 6.5.6
unknown
[en] The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload' function in all versions up to, and including, 6.5.5. This makes it possible for authenticated attackers, with S...
- Affected:
- up to 6.5.6
- Fixed in:
- 6.5.6
- Disclosed:
- Sep 10, 2024
CVE-2024-7770 on NVD →
Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress <= 6.5.5 - Authenticated (Subscriber+) Arbitrary File Upload
high
The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload' function in all versions up to, and including, 6.5.5. This makes it possible for authenticated attackers, with Subscr...
- CVSS:
- 8.8
- Affected:
- up to 6.5.5
- Fixed in:
- 6.5.6
- Disclosed:
- Sep 9, 2024
CVE-2024-7770 on NVD →
Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress [file-manager] >= 6.0 - <= 6.5.5
unknown
[en] The Bit File Manager plugin for WordPress is vulnerable to Remote Code Execution in versions 6.0 to 6.5.5 via the 'checkSyntax' function. This is due to writing a temporary file to a publicly accessible directory before performing file validation. This makes it possible for unauthenticated attackers to execute cod...
- Affected:
- 6.0 – 6.5.5
- Fixed in:
- 6.5.5
- Disclosed:
- Sep 5, 2024
CVE-2024-7627 on NVD →
Bit File Manager 6.0 - 6.5.5 - Unauthenticated Remote Code Execution via Race Condition
high
The Bit File Manager plugin for WordPress is vulnerable to Remote Code Execution in versions 6.0 to 6.5.5 via the 'checkSyntax' function. This is due to writing a temporary file to a publicly accessible directory before performing file validation. This makes it possible for unauthenticated attackers to execute code on...
- CVSS:
- 8.1
- Affected:
- 6.0 – 6.5.5
- Fixed in:
- 6.5.6
- Disclosed:
- Sep 4, 2024
CVE-2024-7627 on NVD →
Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress [file-manager] < 6.0
unknown
[en] Deserialization of Untrusted Data vulnerability in File Manager by Bit Form Team File Manager – 100% Free & Open Source File Manager Plugin for WordPress | Bit File Manager.This issue affects File Manager – 100% Free & Open Source File Manager Plugin for WordPress | Bit File Manager: from n/a through 5.2.7.
- Affected:
- up to 6.0
- Fixed in:
- 6.0
- Disclosed:
- Dec 20, 2023
CVE-2022-47599 on NVD →
Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress [file-manager] < 6.3
unknown
[en] The File Manager WordPress plugin before 6.3 does not restrict the file managers root directory, allowing an administrator to set a root outside of the WordPress root directory, giving access to system files and directories even in a multisite setup, where site administrators should not be allowed to modify the si...
- Affected:
- up to 6.3
- Fixed in:
- 6.3
- Disclosed:
- Dec 11, 2023
CVE-2023-5907 on NVD →
File Manager <= 6.3 - Authenticated (Admin+) Arbitrary OS File Access via Path Traversal
low
The File Manager – 100% Free & Open Source File Manager Plugin for WordPress | Bit File Manager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.2 via the Root Folder Path setting. This makes it possible for authenticated attackers, with administrative-level access and above,...
- CVSS:
- 2.2
- Affected:
- up to 6.2
- Fixed in:
- 6.3
- Disclosed:
- Nov 20, 2023
CVE-2023-5907 on NVD →
Bit File Manager <= 5.2.7 - Authenticated (Admin+) PHP Object Injection
high
The Bit File Manager plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.2.7 via deserialization of untrusted input from the 'language' setting parameter. This allows authenticated attackers, with administrative privileges and above, to inject a PHP Object. No POP chain is pre...
- CVSS:
- 7.2
- Affected:
- up to 5.2.7
- Fixed in:
- 6.0
- Disclosed:
- Apr 28, 2023
CVE-2022-47599 on NVD →
Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress [file-manager] < 5.2.3
unknown
[en] The Library File Manager WordPress plugin before 5.2.3 is using an outdated version of the elFinder library, which is know to be affected by security issues (CVE-2021-32682), and does not have any authorisation as well as CSRF checks in its connector AJAX action, allowing any authenticated users, such as subscribe...
- Affected:
- up to 5.2.3
- Fixed in:
- 5.2.3
- Disclosed:
- Apr 4, 2022
CVE-2022-0403 on NVD →
Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress [file-manager] < 5.2.3
unknown
Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress Library File Manager plugin (versions <= 5.2.2).
- Affected:
- up to 5.2.3
- Fixed in:
- 5.2.3
- Disclosed:
- Mar 30, 2022
Bit File Manager – 100% free file manager for WordPress <= 5.2.2 - Subscriber+ Arbitrary File Creation/Upload/Deletion
high
The Library File Manager WordPress plugin before 5.2.3 is using an outdated version of the elFinder library, which is known to be affected by security issues (CVE-2021-32682), and does not have any authorisation as well as CSRF checks in its connector AJAX action, allowing any authenticated users, such as subscriber to...
- CVSS:
- 8.8
- Affected:
- up to 5.2.2
- Fixed in:
- 5.2.3
- Disclosed:
- Mar 14, 2022
CVE-2022-0403 on NVD →
Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress [file-manager] < 5.2.3
unknown
[en] elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerabilities can allow an attacker to execute arbitrary code and commands on the server hosting the elFinder PHP connector, even with minimal configuration. The issues we...
- Affected:
- up to 5.2.3
- Fixed in:
- 5.2.3
- Disclosed:
- Jun 14, 2021
CVE-2021-32682 on NVD →
Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress [file-manager] < 4.9
unknown
Multiple Vulnerabilities found by WebARX in WordPress File Manager plugin (versions <= 4.8).
- Affected:
- up to 4.9
- Fixed in:
- 4.9
- Disclosed:
- Jul 10, 2019
Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress [file-manager] < 5.0.2
unknown
[en] inc/logger.php in the Giribaz File Manager plugin before 5.0.2 for WordPress logged activity related to the plugin in /wp-content/uploads/file-manager/log.txt. If a user edits the wp-config.php file using this plugin, the wp-config.php contents get added to log.txt, which is not protected and contains database cre...
- Affected:
- up to 5.0.2
- Fixed in:
- 5.0.2
- Disclosed:
- Mar 7, 2018
CVE-2018-7204 on NVD →
Bit File Manager <= 5.0.0 - Information Disclosure
high
inc/logger.php in the Giribaz File Manager plugin before 5.0.2 for WordPress logged activity related to the plugin in /wp-content/uploads/file-manager/log.txt. If a user edits the wp-config.php file using this plugin, the wp-config.php contents get added to log.txt, which is not protected and contains database credenti...
- CVSS:
- 7.5
- Affected:
- up to 5.0.0
- Fixed in:
- 5.0.2
- Disclosed:
- Mar 2, 2018
CVE-2018-7204 on NVD →
Bit File Manager <= 4.1.4 - Cross-Site Request Forgery to Arbitrary File Upload
high
The Bit File Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.4. This is due to missing or incorrect nonce validation on the plugin's upload form. This makes it possible for unauthenticated attackers to upload arbitrary files to the server via a forged reque...
- CVSS:
- 8.8
- Affected:
- up to 4.1.5
- Fixed in:
- 4.1.5
- Disclosed:
- Mar 1, 2017
Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress [file-manager] < 4.1.5
unknown
The Bit File Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.4. This is due to missing or incorrect nonce validation on the plugin's upload form. This makes it possible for unauthenticated attackers to upload arbitrary files to the server via a forged reque...
- Affected:
- up to 4.1.5
- Fixed in:
- 4.1.5
- Disclosed:
- Mar 1, 2017
Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress [file-manager] < 4.1.5
unknown
The File Manager WordPress plugin was affected by a Cross-Site Request Forgery (CSRF) Arbitrary File Upload security vulnerability.
- Affected:
- up to 4.1.5
- Fixed in:
- 4.1.5
Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress [file-manager] < 6.8
unknown
- Affected:
- up to 6.8
- Fixed in:
- 6.8
CVE-2025-1725 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database