Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-6382 -- CVSS 9.1 Vulnerability Briefing

CVE-2026-6382 | CVSS 9.1 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-6382 is a critical-severity vulnerability affecting multiple WordPress file management plugins: FileOrganizer (before 1.1.9), Advanced File Manager (before 5.4.12), File Manager Pro (before 2.1.1), and File Manager (before 8.0.4), all of which expose file system functionality within WordPress installations.

Technical Detail

The CVE description is incomplete in the available data, and the precise flaw mechanism has not been fully disclosed at this time. Based on the affected plugin category and the critical CVSS score of 9.1, the vulnerability likely involves improper access controls or insufficient input validation within file management functionality, which could allow an attacker to perform unauthorized file operations such as arbitrary file upload, read, or deletion. If exploited, the most probable impact would be remote code execution or full site compromise, as file manager plugins by nature interact directly with the server file system and are a historically high-value target in WordPress environments.

Exploitation Status

No known exploit exists for this vulnerability at this time. It is not listed in the CISA Known Exploited Vulnerabilities catalog as of July 12, 2026. While no public proof-of-concept or active exploitation has been confirmed, the critical severity rating and the widespread deployment of the affected plugins make this a high-priority patching target regardless of current exploit availability.

Who Is Targeting This

No specific threat actor attribution at this time. Neither confirmed nor reported threat actor associations have been identified in connection with this CVE. No campaigns or targeted sectors have been linked to this vulnerability in available intelligence.

What To Do

Update all affected plugins to their respective patched versions immediately: FileOrganizer to 1.1.9 or later, Advanced File Manager to 5.4.12 or later, File Manager Pro to 2.1.1 or later, and File Manager to 8.0.4 or later. Site administrators who cannot patch immediately should consider deactivating the affected plugins until updates can be applied, as file manager plugins present a significant attack surface when unpatched. Detection efforts should focus on monitoring for unexpected file creation or modification events in the WordPress web root, anomalous PHP file uploads, and unauthorized access to plugin-specific admin endpoints. Given the critical CVSS score and the plugin category involved, treat this as a high-priority patch even in the absence of confirmed active exploitation.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →