{"api_version":"1","generated_at":"2026-08-10T11:34:08+00:00","cve":"CVE-2026-17541","urls":{"html":"https://cve.report/CVE-2026-17541","api":"https://cve.report/api/cve/CVE-2026-17541.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-17541","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-17541"},"summary":{"title":"Bit File Manager < 6.9.1 - Unauthenticated File Activity Log Disclosure","description":"The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to read its file activity log, disclosing the file operations performed on the site, the paths involved and the name of the user who performed them.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-08-10 07:16:49","updated_at":"2026-08-10 07:16:49"},"problem_types":["CWE-200 Information Exposure"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/972bf72f-08c4-41ec-b6e9-2d6083d21734/","name":"https://wpscan.com/vulnerability/972bf72f-08c4-41ec-b6e9-2d6083d21734/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-17541","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-17541","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"File Manager","version":"affected 6.9.1 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Farid Narimanov","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"File Manager","vendor":"Unknown","versions":[{"lessThan":"6.9.1","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Farid Narimanov"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to read its file activity log, disclosing the file operations performed on the site, the paths involved and the name of the user who performed them."}],"problemTypes":[{"descriptions":[{"description":"CWE-200 Information Exposure","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-10T06:00:10.691Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/972bf72f-08c4-41ec-b6e9-2d6083d21734/"}],"source":{"discovery":"EXTERNAL"},"title":"Bit File Manager < 6.9.1 - Unauthenticated File Activity Log Disclosure","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-17541","datePublished":"2026-08-10T06:00:10.691Z","dateReserved":"2026-07-27T10:00:18.731Z","dateUpdated":"2026-08-10T06:00:10.691Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-10 07:16:49","lastModifiedDate":"2026-08-10 07:16:49","problem_types":["CWE-200 Information Exposure"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"17541","Ordinal":"1","Title":"Bit File Manager < 6.9.1 - Unauthenticated File Activity Log Dis","CVE":"CVE-2026-17541","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"17541","Ordinal":"1","NoteData":"The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to read its file activity log, disclosing the file operations performed on the site, the paths involved and the name of the user who performed them.","Type":"Description","Title":"Bit File Manager < 6.9.1 - Unauthenticated File Activity Log Dis"}]}}}