Access violation vulnerability in FileBird – WordPress Media Library Folders & File Manager 6.4.9

The FileBird plugin for WordPress allows you to organize your media library into folders and manage your files. However, it has a security issue where unauthorized people can make changes to the data without permission. This is because the plugin does not check if the user has the right capabilities before allowing access to the /filebird/v1/fb-wipe-clear-all-data function. This means that someone with author-level access or higher can reset all the plugin’s settings.

Detected in:

FileBird – WordPress Media Library Folders & File Manager fixed vulnerable versions: >= * <= 6.4.9

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.