CVE · Medium

CVE-2023-25966 — FileBird – WordPress Media Library Folders & File Manager [filebird] < 5.1.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-25966 FileBird – WordPress Media Library Folders & File Manager [filebird] < 5.1.5 Missing Authorization Medium 5.5 < 5.1.5 5.1.5 2023-03-27

CVE-2023-25966

The FileBird plugin for WordPress before version 5.1.5 allows authenticated users with author-level permissions to generate API keys without proper authorization checks. The vulnerability exists in the resAdminPermissionsCheck callback function, which fails to verify user capabilities before allowing API key generation. An attacker with basic contributor or author access could exploit this to set their own API key.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.