PLUGIN SECURITY
Is Filebird safe?
Organize thousands of WordPress media files in folders / categories with ease.
What this plugin does
- Slug:
filebird - Author: Ninja Team
- 200000+ active installs
- 94/100 rating (1120 reviews on wordpress.org)
- 7074317 all-time downloads
- On WordPress.org since 2018-07-02
file managermediamedia foldersorganizationWordPress media library folders
Maintenance status
- Latest known version: 6.5.7
- Last updated: 2026-08-22 7:57am GMT
- Tested up to WordPress: 7.1
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
11 known CVEs on file for Filebird.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2025-12900 | FileBird – WordPress Media Library Folders & File Manager [filebird] < 6.5.2 | Missing Authorization | Medium 4.3 | < 6.5.2 | 6.5.2 | 2025-12-15 | ✓ fixed in latest |
| CVE-2025-11510 | FileBird – WordPress Media Library Folders & File Manager [filebird] < 6.5.0 | Improper Authorization | Medium 4.3 | < 6.5.0 | 6.5.0 | 2025-10-17 | ✓ fixed in latest |
| CVE-2025-26977 | FileBird – WordPress Media Library Folders & File Manager [filebird] < 6.4.6 | Authorization Bypass Through User-Controlled Key | Low 3.8 | < 6.4.6 | 6.4.6 | 2025-02-23 | ✓ fixed in latest |
| CVE-2024-53825 | FileBird – WordPress Media Library Folders & File Manager [filebird] < 6.3.4 | Missing Authorization | Medium 4.7 | < 6.3.4 | 6.3.4 | 2024-12-02 | ✓ fixed in latest |
| CVE-2024-35166 | FileBird – WordPress Media Library Folders & File Manager [filebird] < 5.6.4 | Exposure of Sensitive Information to an Unauthorized Actor | High 7.5 | < 5.6.4 | 5.6.4 | 2024-05-10 | ✓ fixed in latest |
| CVE-2024-2346 | FileBird – WordPress Media Library Folders & File Manager [filebird] < 5.6.4 | Authorization Bypass Through User-Controlled Key | Medium 5.4 | < 5.6.4 | 5.6.4 | 2024-04-16 | ✓ fixed in latest |
| CVE-2024-2345 | FileBird – WordPress Media Library Folders & File Manager [filebird] < 5.6.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.6.4 | 5.6.4 | 2024-04-16 | ✓ fixed in latest |
| CVE-2024-0691 | FileBird – WordPress Media Library Folders & File Manager [filebird] < 5.6.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 5.6.1 | 5.6.1 | 2024-01-19 | ✓ fixed in latest |
+ 5 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2023-25966 | FileBird – WordPress Media Library Folders & File Manager [filebird] < 5.1.5 | Missing Authorization | Medium 5.5 | < 5.1.5 | 5.1.5 | 2023-03-27 | ✓ fixed in latest |
| CVE-2021-24385 | FileBird – WordPress Media Library Folders & File Manager [filebird] < 4.7.4 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Critical 9.8 | < 4.7.4 | 4.7.4 | 2021-06-16 | ✓ fixed in latest |
| — | FileBird – WordPress Media Library Folders & File Manager [filebird] < 6.4.9 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Medium 6.5 | < 6.4.9 | 6.4.9 | 0000-00-00 | ✓ fixed in latest |
| CVE-2024-0691 | FileBird < 5.6.1 - Admin+ Stored XSS | — | Unknown | < 5.6.1 | 5.6.1 | — | ✓ fixed in latest |
| CVE-2025-6986 | FileBird – WordPress Media Library Folders & File Manager < 6.4.9 - Authenticated (Author+) SQL Injection | — | Unknown | < 6.4.9 | 6.4.9 | — | ✓ fixed in latest |
How to fix it
Keep Filebird updated — 6.5.7 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- File Manager — 1000000+ active installs — 92/100 (1488)
- Safe SVG — 1000000+ active installs — 98/100 (79) — max PHP 8.4
- FileOrganizer – WordPress File Manager — 200000+ active installs — 96/100 (48) — max PHP 8.4
- Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution — 100000+ active installs — 96/100 (438) — max PHP 8.4
- File Manager Pro – Filester — 100000+ active installs — 98/100 (152)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.