Impact
The FileBird Pro plugin contains a missing authorization check that permits users to view or manipulate files without proper permission validation. This can lead to unauthorized access to media and other protected assets, compromising confidentiality and integrity of the site data. The weakness is identified as CWE-862.
Affected Systems
The vulnerability is present in all supported installations of the NinjaTeam FileBird Pro WordPress plugin up to and including version 6.5.1. WordPress sites deploying this plugin via any hosting environment are susceptible if the plugin’s access control levels are misconfigured.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it by accessing the plugin’s file management endpoints over the web, assuming the target site permits user interactions with the plugin’s interface.
OpenCVE Enrichment