WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in File Manager

Manage WordPress files and folders from your dashboard with a built-in code editor: upload, edit, delete, move, rename, and archive, no FTP needed.

16Reported vulnerabilities
9.8Highest CVSS score
6.9.1Latest version
10,000+Active installs

What to do now

Update File Manager to 6.9.1 or later. 16 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 3, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2023-6846 High 8.8 15.9% 8.3.4 and earlier 8.3.5 February 5, 2024
CVE-2023-5907 Medium 6.5 0.9% Before 6.3 6.3 December 11, 2023
CVE-2018-25105 Critical 9.8 0.8% 3.0 and earlier 3.1 October 16, 2024
CVE-2018-16363 Medium 5.4 1.4% 2.9 to 2.9 (inclusive) 3.0 September 7, 2018
CVE-2021-24177 Medium 5.4 0.9% Before 7.1 7.1 April 5, 2021
CVE-2024-7770 High 8.8 1.1% Before 6.5.6 6.5.6 September 10, 2024
CVE-2024-7627 High 8.1 2.8% 6.0 up to (but not including) 6.5.6 6.5.6 September 5, 2024
CVE-2026-15991 High 8.8 0.6% 6.0 to 6.9 (inclusive) 6.9.1 August 6, 2026
WF-37052cb9-8479-4004-9161-65f37028ae10 High 8.8 Before 4.1.5 4.1.5 March 1, 2017
CVE-2018-7204 High 7.5 2.8% 5.0.0 and earlier 5.0.2 March 7, 2018
CVE-2022-47599 High 7.2 0.5% Before 6.0.0 6.0.0 December 20, 2023
CVE-2024-8743 Medium 6.8 0.8% 6.5.7 and earlier 6.5.8 October 4, 2024
CVE-2026-17540 Medium 6.5 0.3% 6.9.0 and earlier 6.9.1 August 4, 2026
CVE-2025-1725 Medium 6.4 0.2% 0 to 6.7 (inclusive) 6.8 June 3, 2025
CVE-2026-17541 Medium 5.3 0.3% 6.9.0 and earlier 6.9.1 August 4, 2026
CVE-2026-17542 Medium 4.3 0.3% 6.9.0 and earlier 6.9.1 August 4, 2026

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.