Junglewise Threat Intelligence

CVE-2026-17540: Bit File Manager arbitrary file read and deletion via authorization bypass

CVE-2026-17540 · Severity: high · CVSS 8.8 · Published 2026-08-10

Vendors: Bit Apps.

Executive brief

Bit File Manager is a WordPress plugin for browsing and managing files within a WordPress installation. A vulnerability in versions before 6.9.1 allows any logged-in user, even one with minimal permissions (such as a Subscriber), to read and delete arbitrary files under the WordPress directory. This could expose sensitive configuration files containing database credentials and authentication keys, and disable the website through deletion of critical files.

Technical details

The plugin fails to properly validate authorization on its file management commands, specifically by checking for the presence of the "cmd" parameter in the request body while accepting commands from the query string. Authenticated users can bypass permission checks by sending file read and delete commands exclusively in the query string, omitting them from the POST body. The vulnerability requires WordPress authentication but no additional plugin-level permissions; WordPress issues REST nonces to all logged-in users, which the plugin accepts. An attacker can read arbitrary files (including wp-config.php) and delete files required for site operation, causing denial of service. The issue is fixed in version 6.9.1.

Affected products

  • Bit Apps File Manager before 6.9.1

Timeline

  • 2026-08-04: disclosed
  • 2026-09-24: patched: version 6.9.1 released

References