The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to missing authorization in all versions up to, and including, 6.5.1 via the "ConvertController::insertToNewTable" function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with author level access and above, to inject global folders and reassign arbitrary media attachments to those folders under certain circumstances.
References
Configurations
No configuration.
History
No history.
Information
Published : 2025-12-15 15:15
Updated : 2025-12-15 18:22
NVD link : CVE-2025-12900
Mitre link : CVE-2025-12900
CVE.ORG link : CVE-2025-12900
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
