CVE Database /
CVE-2021-24385
CVE · Critical
CVE-2021-24385 — FileBird – WordPress Media Library Folders & File Manager [filebird] < 4.7.4
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-24385
|
FileBird – WordPress Media Library Folders & File Manager [filebird] < 4.7.4 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
Critical
9.8
|
< 4.7.4
|
4.7.4 |
2021-06-16 |
—
|
CVE-2021-24385
The FileBird plugin versions prior to 4.7.4 contain a SQL injection flaw in which user-supplied data from HTTP POST requests is directly passed to database queries without proper sanitization. An unauthenticated attacker can exploit this vulnerability through an unprotected REST API endpoint to execute arbitrary SQL commands. The lack of input validation and missing permission checks on the affected endpoint make this a critical security issue.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings