{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/file-manager-6.0-6.9/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-15991"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["File Manager (6.0-6.9)"],"_cs_severities":["high"],"_cs_tags":["web-application-vulnerability","wordpress","remote-code-execution","arbitrary-file-deletion"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe File Manager plugin for WordPress (versions 6.0 through 6.9) is vulnerable to an arbitrary file deletion flaw caused by insufficient path validation within its connector function. The vulnerability arises from a discrepancy between how the elFinder library processes request parameters for permission handlers versus command dispatching. Authenticated users with subscriber-level access can manipulate the request by utilizing a POST request with specific cmd or cmf parameters. Because the library's bind registration ignores these commands while the dispatcher processes them using the merged $_GET and $_POST superglobals, an attacker can bypass security controls to target files relative to the WordPress ABSPATH. The ability to delete critical files such as wp-config.php can facilitate a subsequent remote code execution (RCE) attack, making this a high-impact vulnerability for WordPress environments.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated attacker to delete arbitrary files on the underlying web server, potentially compromising the integrity and availability of the WordPress site. By deleting key configuration files like wp-config.php, an attacker can trigger a re-installation process or intercept database credentials, leading to full server compromise and RCE. This vulnerability affects any WordPress instance running the File Manager plugin between versions 6.0 and 6.9.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the File Manager plugin for WordPress to the latest available version immediately to remediate the path validation logic.\u003c/li\u003e\n\u003cli\u003eMonitor web access logs for POST requests to the file manager connector endpoint containing suspicious query parameters such as cmd=rm or cmf=file.\u003c/li\u003e\n\u003cli\u003eAudit user roles within WordPress to ensure unauthorized users do not possess subscriber-level access or higher if not strictly required for site operation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-06T05:21:45Z","date_published":"2026-08-06T05:21:45Z","id":"https://feed.craftedsignal.io/briefs/2026-08-file-manager-plugin-rce/","summary":"The WordPress File Manager plugin (versions 6.0-6.9) contains an arbitrary file deletion vulnerability allowing authenticated attackers to delete critical server files and achieve remote code execution.","title":"Arbitrary File Deletion Vulnerability in WordPress File Manager Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-file-manager-plugin-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - File Manager (6.0-6.9)","version":"https://jsonfeed.org/version/1.1"}