We have tested this on client servers and we don't get access to all that root, just the one in the user's account.
Maybe you should open a one-time support ticket to the CWP team to check your server. Maybe this is a misconfiguration of the server itself.
Hello,
First of all, I recommend the owner not to use such file manager plugins. Because with this type of add-ons; If a plugin, theme or special software is a security problem, they install malicious software on the server using this type of wp-file-manager plug-ins.
But I have an opinion like this;
Does this WP-FILE-MANAGER plugin work with shell logic? With Cloudlinux, if the necessary precautions are not taken on servers that do not install CageFS, you can access the root directory with shell files, although access is limited due to read and write permissions, it is a sufficient reason to cause damage.
The fact that I have ROOT access via PHP at the moment has not brought a different thought to my mind.