---
id: CVE-2026-19708
title: >-
  The File Manager WordPress plugin before 8.0.5 does not prevent
  unauthenticated users from downloading its database backup archives, and in
  some cases writes them under a fixed filename, allowing unauthenticated
  attackers to retrieve a f…
summary: >-
  The File Manager WordPress plugin before 8.0.5 does not prevent
  unauthenticated users from downloading its database backup archives, and in
  some cases writes them under a fixed filename, allowing unauthenticated
  attackers to retrieve a f…
severity: none
cwe:
  - CWE-200
product: File Manager
affected:
  - file_manager >= 7.2.2 < 8.0.5
published: '2026-09-26'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T07:17:02.397'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19708'
references:
  - url: 'https://wpscan.com/vulnerability/a0cbfd20-7741-44d0-96c4-054a7952f81b/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-26T06:27:03.681Z'
---

## Overview

The File Manager WordPress plugin before 8.0.5 does not prevent unauthenticated users from downloading its database backup archives, and in some cases writes them under a fixed filename, allowing unauthenticated attackers to retrieve a full database dump including every user's email address and password hash on servers that do not apply the directory's .htaccess file.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
