The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a subscriber, to read and delete arbitrary files under the WordPress installation directory, which could lead to the disclosure of the site's configuration secrets and to denial of service.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
The File Manager WordPress plugin before version 6.9.1 contains an improper authorization vulnerability (CWE-284) that allows any authenticated user—including low-privilege accounts like subscribers—to execute file management commands without proper permission checks. This means attackers can read sensitive files such as wp-config.php (containing database credentials and security keys) and delete arbitrary files within the WordPress installation directory, leading to information disclosure and potential denial of service. The vulnerability is particularly dangerous because it only requires basic authentication, a credential level many WordPress sites grant liberally, making exploitation trivial for insiders or accounts compromised through phishing.
While this CVE currently maps to zero Casky skills due to its lack of MITRE ATT&CK technique alignment, practitioners using Casky's Claude-powered analysis would typically identify this attack pattern through skill detection around Improper Access Control (CWE-284) and reconnaissance activities. Security teams should monitor for suspicious file access patterns, particularly wp-config.php reads and unexpected file deletions by low-privileged users. Organizations using Casky's extended reasoning capabilities can correlate authentication logs with file system access events to detect exploitation attempts, even without direct ATT&CK mapping. The key defensive signal: authenticated users attempting file operations outside their typical role scope, detectable through activity pattern analysis and behavioral anomaly detection across your security skill inventory.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-17540. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation