WordPress Plugin Vulnerabilities

Bit File Manager < 6.9.1 - Unauthenticated File Activity Log Disclosure

Description

The plugin does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to read its file activity log, disclosing the file operations performed on the site, the paths involved and the name of the user who performed them.

Proof of Concept

Affects Plugins

Fixed in 6.9.1

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE

Miscellaneous

Original Researcher
Farid Narimanov
Submitter
Farid Narimanov
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-08-04 (about 27 days ago)
Added
2026-08-04 (about 26 days ago)
Last Updated
2026-08-04 (about 26 days ago)

Other