CVE-2026-15991 is a missing authorization flaw in the File Manager plugin for WordPress affecting versions 6.0 through 6.9. The vulnerability arises from inconsistent command handling and insufficient authorization enforcement in the plugin’s elFinder-backed connector logic. During bind registration, the command value is read only from POST parameters, while the dispatcher later resolves commands from merged GET and POST input. By placing the command selector in the URL query string of a POST request, an attacker can bypass registration of the permission handler for sensitive operations such as file removal and file access. As a result, an authenticated user with only subscriber-level privileges can invoke unchecked file-related commands against a volume rooted at the WordPress installation directory. This enables arbitrary file read and arbitrary file deletion on the server. Deletion of critical application files can create a path to full compromise, including remote code execution in downstream exploitation scenarios.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical missing authorization vulnerability in the WordPress File Manager plugin that allows authenticated low-privilege users to read and delete arbitrary files, potentially leading to remote code execution and full site compromise.
An arbitrary file deletion vulnerability in the WordPress File Manager plugin (versions 6.0 through 6.9) caused by insufficient file path validation in the connector function. Authenticated attackers with subscriber-level access or higher can read and delete arbitrary files, potentially leading to remote code execution.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.