CVE · Medium

CVE-2024-2346 — FileBird – WordPress Media Library Folders & File Manager [filebird] < 5.6.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-2346 FileBird – WordPress Media Library Folders & File Manager [filebird] < 5.6.4 Authorization Bypass Through User-Controlled Key Medium 5.4 < 5.6.4 5.6.4 2024-04-16

CVE-2024-2346

The FileBird plugin for WordPress contains an insecure direct object reference vulnerability affecting versions 5.6.3 and earlier that allows authenticated users with author-level permissions or greater to delete folders belonging to other users without proper authorization checks. By exploiting this flaw in the folder deletion functionality, attackers can remove folders created by different users and expose those users' uploaded files to visibility. The vulnerability stems from inadequate validation of user-controlled input when processing folder deletion requests.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.