HIGH
bitpressadmin
CVE published 2026-08-06
CVE-2026-15991
The File Manager plugin for WordPress has a critical vulnerability allowing arbitrary file deletion due to insufficient file path validation in versions 6.0-6.9. Authenticated attackers with subscriber-level access can delete files, potentially leading to remote code execution. This vulnerability is highly severe, with a CVSS score of 8.8, and defenders should treat it as high priority due to the potentia [truncated]