Critical Vulnerability in File Manager Plugin for WordPress: CVE-2026-15991
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in versions 6.0 - 6.9. Authenticated attackers with subscriber-level access can read and delete arbitrary files, potentially leading to remote code execution. The vulnerability has a CVSS score of 8.8 and is not actively exploited. Immediate patching or mitigation is recommended.