Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
WordPress Plugin 'WP File Manager' Allows Unauthenticated File Access
MINI-g8w5-6pp8-92g4
Summary
An unpatched vulnerability in the WP File Manager plugin for WordPress allows attackers to access and potentially delete sensitive files on a website without a password. This could lead to data theft or website disruption. Affected sites should update the plugin to the latest version as soon as possible.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| – | coredns-fips-1.11 | All versions | – |
| – | kuma-coredns-fips-1.11 | All versions | – |
Original title
MINI-g8w5-6pp8-92g4
Published: 7 Mar 2026 · Updated: 13 Mar 2026 · First seen: 7 Mar 2026