CVE Database /
CVE-2023-25966
CVE · Medium
CVE-2023-25966 — FileBird – WordPress Media Library Folders & File Manager [filebird] < 5.1.5
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-25966
|
FileBird – WordPress Media Library Folders & File Manager [filebird] < 5.1.5 |
Missing Authorization |
Medium
5.5
|
< 5.1.5
|
5.1.5 |
2023-03-27 |
—
|
CVE-2023-25966
The FileBird plugin for WordPress before version 5.1.5 allows authenticated users with author-level permissions to generate API keys without proper authorization checks. The vulnerability exists in the resAdminPermissionsCheck callback function, which fails to verify user capabilities before allowing API key generation. An attacker with basic contributor or author access could exploit this to set their own API key.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings