CVE-2024-2346
The FileBird plugin for WordPress contains an insecure direct object reference vulnerability affecting versions 5.6.3 and earlier that allows authenticated users with author-level permissions or greater to delete folders belonging to other users without proper authorization checks. By exploiting this flaw in the folder deletion functionality, attackers can remove folders created by different users and expose those users' uploaded files to visibility. The vulnerability stems from inadequate validation of user-controlled input when processing folder deletion requests.
Based on public CVE data (MITRE/NVD).