{"id":"CVE-2026-19708","title":"The File Manager WordPress plugin before 8.0.5 does not prevent unauthenticated users from downloading its database backup archives, and in some cases writes them under a fixed filename, allowing unauthenticated attackers to retrieve a f…","summary":"The File Manager WordPress plugin before 8.0.5 does not prevent unauthenticated users from downloading its database backup archives, and in some cases writes them under a fixed filename, allowing unauthenticated attackers to retrieve a f…","severity":"none","cwe":["CWE-200"],"product":"File Manager","affected":["file_manager >= 7.2.2 < 8.0.5"],"published":"2026-09-26","updated":"2026-09-26","sourceUpdated":"2026-09-26T07:17:02.397","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-19708","references":[{"url":"https://wpscan.com/vulnerability/a0cbfd20-7741-44d0-96c4-054a7952f81b/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-26T06:27:03.681Z","slug":"CVE-2026-19708","body":"## Overview\n\nThe File Manager WordPress plugin before 8.0.5 does not prevent unauthenticated users from downloading its database backup archives, and in some cases writes them under a fixed filename, allowing unauthenticated attackers to retrieve a full database dump including every user's email address and password hash on servers that do not apply the directory's .htaccess file.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}