CVE-2026-19708: Unknown File Manager
Medium severity, CVSS 5.9. EPSS: 0.2% chance of exploitation in the next 30 days.
The File Manager WordPress plugin before 8.0.5 does not prevent unauthenticated users from downloading its database backup archives, and in some cases writes them under a fixed filename, allowing unauthenticated attackers to retrieve a full database dump including every user's email address and password hash on servers that do not apply the directory's .htaccess file.
Affected products
- Unknown File Manager: from 7.2.2, before 8.0.5 (fixed in 8.0.5)
Published 2026-09-26. Last modified 2026-09-28.