Executive brief
The File Manager WordPress plugin before version 8.0.5 allows unauthenticated attackers to download database backup files that contain sensitive data including all user email addresses and password hashes. On servers where the directory's .htaccess file is not properly configured, attackers can retrieve a complete database dump without needing valid credentials, potentially leading to account takeover and unauthorized system access.
Technical details
The plugin fails to implement access controls on database backup archive files, allowing unauthenticated network-based access via direct file requests. In some cases backups are stored with predictable filenames, further reducing the attack difficulty. The vulnerability requires the web server's .htaccess protections to be absent or misconfigured; proper file access restrictions would mitigate this issue.
Affected products
- 10web File Manager 7.2.2 through 8.0.4
Timeline
- 2026-09-24: disclosed
- 2026-09-26: patched: Fixed in version 8.0.5