CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-17541

highCVSS 7.5covered by 1 sourcefirst seen 2026-08-10
The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to read its file activity log, disclosing the file operations performed on the site, the paths involved and the name of the user who performed them.

⚡ Watch CVE-2026-17541

Get an email if CVE-2026-17541 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-17541

CVE.org record

Embed the live status

CVE-2026-17541 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-17541 status](https://www.csirts.com/badge/CVE-2026-17541)](https://www.csirts.com/cve/CVE-2026-17541)