Executive brief
Bit File Manager is a popular WordPress plugin that provides a file browser and management interface for site administrators. The plugin fails to properly restrict access to its file browsing endpoint, allowing any logged-in user (including low-privilege accounts like subscribers) to browse the entire WordPress installation directory and download sensitive files such as backups, archives, and documents. This can expose configuration files, database backups, and other confidential data stored on the server.
Technical details
The vulnerability is an authorization bypass (missing capability check) in the bitapps_fm_connector AJAX action endpoint. Authenticated users can invoke the cmd=open, cmd=search, and cmd=file actions to enumerate the WordPress ABSPATH root directory and recursively search for and download files with certain MIME types (images, PDFs, archives, documents), bypassing the plugin's admin capability requirement. Attack preconditions include a valid logged-in session (any authenticated user) and a WordPress REST nonce issued to all logged-in users. The plugin does enforce file-type restrictions on certain operations (e.g., wp-config.php and PHP files cannot be downloaded) and requires authentication, but the authorization layer is entirely missing. A fix is available in version 6.9.1 and later.
Affected products
- Bit Apps File Manager before 6.9.1
Timeline
- 2026-08-04: disclosed
- 2026-08-10: patched: Fixed in version 6.9.1