CVE · Low

CVE-2025-26977 — FileBird – WordPress Media Library Folders & File Manager [filebird] < 6.4.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-26977 FileBird – WordPress Media Library Folders & File Manager [filebird] < 6.4.6 Authorization Bypass Through User-Controlled Key Low 3.8 < 6.4.6 6.4.6 2025-02-23

CVE-2025-26977

A security flaw exists in FileBird plugin versions prior to 6.4.2.1 that allows authorized users with at least author privileges to bypass intended restrictions when accessing specific files or folders within the WordPress media library due to inadequate verification of a user-input parameter. This vulnerability can be exploited by attackers who have successfully authenticated and possess sufficient permissions, enabling them to perform unauthorized actions on the affected system.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.