WordPress Plugin Vulnerabilities
Bit File Manager < 6.9.1 - Unauthenticated File Activity Log Disclosure
Description
The plugin does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to read its file activity log, disclosing the file operations performed on the site, the paths involved and the name of the user who performed them.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
SENSITIVE DATA DISCLOSURE
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Farid Narimanov
Submitter
Farid Narimanov
Submitter website
Submitter twitter
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-08-04 (about 27 days ago)
Added
2026-08-04 (about 26 days ago)
Last Updated
2026-08-04 (about 26 days ago)