FileBird – WordPress Media Library Folders & File Manager <= 6.5.1 - Missing Authorization to Authenticated (Author+) Global Folders Tampering
medium
The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to missing authorization in all versions up to, and including, 6.5.1 via the "ConvertController::insertToNewTable" function due to missing validation on a user controlled key. This makes it possible for authenticated attack...
- CVSS:
- 4.3
- Affected:
- up to 6.5.1
- Fixed in:
- 6.5.2
- Disclosed:
- Dec 15, 2025
CVE-2025-12900 on NVD →
FileBird – WordPress Media Library Folders & File Manager [filebird] < 6.5.2
unknown
[en] The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to missing authorization in all versions up to, and including, 6.5.1 via the "ConvertController::insertToNewTable" function due to missing validation on a user controlled key. This makes it possible for authenticated a...
- Affected:
- up to 6.5.2
- Fixed in:
- 6.5.2
- Disclosed:
- Dec 15, 2025
CVE-2025-12900 on NVD →
FileBird – WordPress Media Library Folders & File Manager [filebird] < 6.5.0
unknown
[en] The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /filebird/v1/fb-wipe-clear-all-data function in all versions up to, and including, 6.4.9. This makes it possible for authenticated attackers...
- Affected:
- up to 6.5.0
- Fixed in:
- 6.5.0
- Disclosed:
- Oct 18, 2025
CVE-2025-11510 on NVD →
FileBird <= 6.4.9 - Improper Authorization to Authenticated (Author+) Settings Reset
medium
The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /filebird/v1/fb-wipe-clear-all-data function in all versions up to, and including, 6.4.9. This makes it possible for authenticated attackers, wit...
- CVSS:
- 4.3
- Affected:
- up to 6.4.9
- Fixed in:
- 6.5.0
- Disclosed:
- Oct 17, 2025
CVE-2025-11510 on NVD →
FileBird – WordPress Media Library Folders & File Manager <= 6.4.8 - Authenticated (Author+) SQL Injection
medium
The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in all versions up to, and including, 6.4.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes i...
- CVSS:
- 6.5
- Affected:
- up to 6.4.8
- Fixed in:
- 6.4.9
- Disclosed:
- Aug 5, 2025
CVE-2025-6986 on NVD →
FileBird – WordPress Media Library Folders & File Manager [filebird] < 6.4.6
unknown
[en] Authorization Bypass Through User-Controlled Key vulnerability in Ninja Team Filebird allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Filebird: from n/a through 6.4.2.1.
- Affected:
- up to 6.4.6
- Fixed in:
- 6.4.6
- Disclosed:
- Feb 25, 2025
CVE-2025-26977 on NVD →
Filebird <= 6.4.2.1 - Authenticated (Author+) Insecure Direct Object Reference
medium
The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.4.2.1 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access and above, t...
- CVSS:
- 4.3
- Affected:
- up to 6.4.2.1
- Fixed in:
- 6.4.6
- Disclosed:
- Feb 23, 2025
CVE-2025-26977 on NVD →
FileBird – WordPress Media Library Folders & File Manager [filebird] < 5.1.5
unknown
[en] Missing Authorization vulnerability in Ninja Team Filebird allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Filebird: from n/a through 5.1.4.
- Affected:
- up to 5.1.5
- Fixed in:
- 5.1.5
- Disclosed:
- Dec 9, 2024
CVE-2023-25966 on NVD →
FileBird – WordPress Media Library Folders & File Manager [filebird] < 6.3.4
unknown
[en] Missing Authorization vulnerability in Ninja Team Filebird allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Filebird: from n/a through 6.3.2.
- Affected:
- up to 6.3.4
- Fixed in:
- 6.3.4
- Disclosed:
- Dec 6, 2024
CVE-2024-53825 on NVD →
Filebird <= 6.3.2 - Missing Authorization
medium
The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.3.2. This makes it possible for authenticated attackers, with Author-level access and above, to perform an unaut...
- CVSS:
- 4.3
- Affected:
- up to 6.3.2
- Fixed in:
- 6.3.4
- Disclosed:
- Dec 2, 2024
CVE-2024-53825 on NVD →
FileBird – WordPress Media Library Folders & File Manager [filebird] < 5.6.4
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team Filebird.This issue affects Filebird: from n/a through 5.6.3.
- Affected:
- up to 5.6.4
- Fixed in:
- 5.6.4
- Disclosed:
- May 13, 2024
CVE-2024-35166 on NVD →
FileBird – WordPress Media Library Folders & File Manager [filebird] < 5.6.4
unknown
[en] The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.3 via folder deletion due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with author ac...
- Affected:
- up to 5.6.4
- Fixed in:
- 5.6.4
- Disclosed:
- May 2, 2024
CVE-2024-2346 on NVD →
FileBird – WordPress Media Library Folders & File Manager [filebird] < 5.6.4
unknown
[en] The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the folder name parameter in all versions up to, and including, 5.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, w...
- Affected:
- up to 5.6.4
- Fixed in:
- 5.6.4
- Disclosed:
- May 2, 2024
CVE-2024-2345 on NVD →
FileBird – WordPress Media Library Folders & File Manager <= 5.6.3 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the folder name parameter in all versions up to, and including, 5.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with a...
- CVSS:
- 6.4
- Affected:
- up to 5.6.3
- Fixed in:
- 5.6.4
- Disclosed:
- Apr 16, 2024
CVE-2024-2345 on NVD →
FileBird – WordPress Media Library Folders & File Manager <= 5.6.3 - Authenticated (Author+) Insecure Direct Object Reference
medium
The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.3 via folder deletion due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with author access...
- CVSS:
- 5.4
- Affected:
- up to 5.6.3
- Fixed in:
- 5.6.4
- Disclosed:
- Apr 16, 2024
CVE-2024-2346 on NVD →
FileBird – WordPress Media Library Folders & File Manager [filebird] < 5.6.1
unknown
[en] The FileBird plugin for WordPress is vulnerable to Stored Cross-Site Scripting via imported folder titles in all versions up to, and including, 5.5.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator access, to inject arbitrary web...
- Affected:
- up to 5.6.1
- Fixed in:
- 5.6.1
- Disclosed:
- Feb 5, 2024
CVE-2024-0691 on NVD →
FileBird <= 5.6.0 - Authenticated(Administrator+) Stored Cross-Site Scripting via Folder Import
medium
The FileBird plugin for WordPress is vulnerable to Stored Cross-Site Scripting via imported folder titles in all versions up to, and including, 5.5.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator access, to inject arbitrary web scrip...
- CVSS:
- 5.5
- Affected:
- up to 5.6.0
- Fixed in:
- 5.6.1
- Disclosed:
- Jan 19, 2024
CVE-2024-0691 on NVD →
FileBird – WordPress Media Library Folders & File Manager [filebird] < 5.6.1
unknown
The FileBird plugin for WordPress is vulnerable to Stored Cross-Site Scripting via imported folder titles in all versions up to, and including, 5.5.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator access, to inject arbitrary web scrip...
- Affected:
- up to 5.6.1
- Fixed in:
- 5.6.1
- Disclosed:
- Jan 19, 2024
Filebird <= 5.1.4 - Missing Authorization via resAdminPermissionsCheck
medium
The Filebird plugin for WordPress is vulnerable to unauthorized SPI key generation due to a missing capability check on the resAdminPermissionsCheck callback function function in versions up to, and including, 5.1.4. This makes it possible for authenticated attackers with author-level access to set the API key.
- CVSS:
- 5.4
- Affected:
- up to 5.1.4
- Fixed in:
- 5.1.5
- Disclosed:
- Mar 27, 2023
CVE-2023-25966 on NVD →
FileBird – WordPress Media Library Folders & File Manager [filebird] < 4.7.4
unknown
[en] The Filebird Plugin 4.7.3 introduced a SQL injection vulnerability as it is making SQL queries without escaping user input data from a HTTP post request. This is a major vulnerability as the user input is not escaped and passed directly to the get_col function and it allows SQL injection. The Rest API endpoint whi...
- Affected:
- up to 4.7.4
- Fixed in:
- 4.7.4
- Disclosed:
- Jul 12, 2021
CVE-2021-24385 on NVD →
Filebird 4.7.3 - Unauthenticated SQL Injection
critical
The Filebird Plugin 4.7.3 introduced a SQL injection vulnerability as it is making SQL queries without escaping user input data from a HTTP post request. This is a major vulnerability as the user input is not escaped and passed directly to the get_col function and it allows SQL injection. The Rest API endpoint which in...
- CVSS:
- 9.8
- Affected:
- 4.7.3 – 4.7.3
- Fixed in:
- 4.7.4
- Disclosed:
- Jun 16, 2021
CVE-2021-24385 on NVD →
FileBird – WordPress Media Library Folders & File Manager [filebird] < 6.4.9
unknown
- Affected:
- up to 6.4.9
- Fixed in:
- 6.4.9
CVE-2025-6986 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database