Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Filebird — verificado contra la base de datos de seguridad local de WP Clinic.
Qué hace este plugin
- Slug:
filebird
- 200000+ instalaciones activas
file managermediamedia foldersorganizationWordPress media library folders
Estado de mantenimiento
- Última versión conocida: 6.5.5
- PHP máximo soportado (analizado): 8.4
Vulnerabilidades conocidas
11 CVEs conocidos registrados para Filebird.
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2025-12900
|
FileBird – WordPress Media Library Folders & File Manager [filebird] < 6.5.2 |
Falta de control de autorización |
Media
4,3
|
< 6.5.2
|
6.5.2 |
2025-12-15 |
✓ corregido en la última versión
|
|
CVE-2025-11510
|
FileBird – WordPress Media Library Folders & File Manager [filebird] < 6.5.0 |
Autorización indebida |
Media
4,3
|
< 6.5.0
|
6.5.0 |
2025-10-17 |
✓ corregido en la última versión
|
|
CVE-2025-26977
|
FileBird – WordPress Media Library Folders & File Manager [filebird] < 6.4.6 |
Elusión de autorización mediante una clave controlada por el usuario |
Baja
3,8
|
< 6.4.6
|
6.4.6 |
2025-02-23 |
✓ corregido en la última versión
|
|
CVE-2024-53825
|
FileBird – WordPress Media Library Folders & File Manager [filebird] < 6.3.4 |
Falta de control de autorización |
Media
4,7
|
< 6.3.4
|
6.3.4 |
2024-12-02 |
✓ corregido en la última versión
|
|
CVE-2024-35166
|
FileBird – WordPress Media Library Folders & File Manager [filebird] < 5.6.4 |
Exposición de información sensible a un actor no autorizado |
Alta
7,5
|
< 5.6.4
|
5.6.4 |
2024-05-10 |
✓ corregido en la última versión
|
|
CVE-2024-2346
|
FileBird – WordPress Media Library Folders & File Manager [filebird] < 5.6.4 |
Elusión de autorización mediante una clave controlada por el usuario |
Media
5,4
|
< 5.6.4
|
5.6.4 |
2024-04-16 |
✓ corregido en la última versión
|
|
CVE-2024-2345
|
FileBird – WordPress Media Library Folders & File Manager [filebird] < 5.6.4 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 5.6.4
|
5.6.4 |
2024-04-16 |
✓ corregido en la última versión
|
|
CVE-2024-0691
|
FileBird – WordPress Media Library Folders & File Manager [filebird] < 5.6.1 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
4,8
|
< 5.6.1
|
5.6.1 |
2024-01-22 |
✓ corregido en la última versión
|
CVE-2025-12900
The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to missing authorization in all versions up to, and including, 6.5.1 via the "ConvertController::insertToNewTable" function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with author level access and above, to inject global folders and reassign arbitrary media attachments to those folders under certain circumstances.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2025-11510
The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /filebird/v1/fb-wipe-clear-all-data function in all versions up to, and including, 6.4.9. This makes it possible for authenticated attackers, with author-level access and above, to reset all of the plugin's configuration data.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2025-26977
The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.4.2.1 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access and above, to perform an unauthorized action
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-53825
The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.3.2. This makes it possible for authenticated attackers, with Author-level access and above, to perform an unauthorized action.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-35166
<p>WordPress Filebird Plugin <= 5.6.3 is vulnerable to Sensitive Data Exposure</p><p>Software: Filebird</p><p>Link: https://wordpress.org/plugins/filebird/#developers</p><p>Affected Version <= 5.6.3</p><p>Fixed in version 5.6.4 </p>
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2024-2346
The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.3 via folder deletion due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with author access or higher, to delete folders created by other users and make their file uploads visible. CVE-2024-35166 may be a duplicate of this issue.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-2345
The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the folder name parameter in all versions up to, and including, 5.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-0691
Update the WordPress Filebird plugin to the latest available version (at least 5.6.1).
Thomas Sanzey discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Filebird Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 5.6.1.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
+ 4 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
—
|
FileBird – WordPress Media Library Folders & File Manager [filebird] < 5.6.1 |
— |
Desconocido
|
< 5.6.1
|
5.6.1 |
2024-01-19 |
✓ corregido en la última versión
|
|
CVE-2023-25966
|
FileBird – WordPress Media Library Folders & File Manager [filebird] < 5.1.5 |
Falta de control de autorización |
Media
5,5
|
< 5.1.5
|
5.1.5 |
2023-03-27 |
✓ corregido en la última versión
|
|
CVE-2021-24385
|
FileBird – WordPress Media Library Folders & File Manager [filebird] < 4.7.4 |
Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) |
Crítica
9,8
|
< 4.7.4
|
4.7.4 |
2021-06-16 |
✓ corregido en la última versión
|
|
CVE-2025-6986
|
FileBird – WordPress Media Library Folders & File Manager [filebird] < 6.4.9 |
Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) |
Media
6,5
|
< 6.4.9
|
6.4.9 |
0000-00-00 |
✓ corregido en la última versión
|
FileBird – WordPress Media Library Folders & File Manager [filebird] < 5.6.1
The FileBird plugin for WordPress is vulnerable to Stored Cross-Site Scripting via imported folder titles in all versions up to, and including, 5.5.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. It may also be possible to socially engineer an administrator into uploading a malicious folder import.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2023-25966
The Filebird plugin for WordPress is vulnerable to unauthorized SPI key generation due to a missing capability check on the resAdminPermissionsCheck callback function function in versions up to, and including, 5.1.4. This makes it possible for authenticated attackers with author-level access to set the API key.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2021-24385
The Filebird Plugin 4.7.3 introduced a SQL injection vulnerability as it is making SQL queries without escaping user input data from a HTTP post request. This is a major vulnerability as the user input is not escaped and passed directly to the get_col function and it allows SQL injection. The Rest API endpoint which invokes this function also does not have any required permissions/authentication and can be accessed by an anonymous user.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2025-6986
The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in all versions up to, and including, 6.4.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Cómo solucionarlo
Mantén Filebird actualizado — 6.5.5 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.
Alternativas más seguras / más establecidas