Description
The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alt text in all versions up to, and including, 6.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-09-18
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch Now
AI Analysis

Impact

The FileBird plugin allows users to attach image alt text, which is stored without proper sanitization or escaping. This oversight permits authenticated users with Author-level permissions or higher to embed arbitrary JavaScript. The resulting stored cross‑site scripting can execute in the browsers of other site visitors, enabling session hijacking, data theft, or defacement.

Affected Systems

Affecting installations of the FileBird WordPress plugin up to and including version 6.5.6. The vulnerability exists in the image handling and gallery rendering modules, as referenced in the plugin source. WordPress sites running any of these versions are exposed.

Risk and Exploitability

The CVSS score of 5.4 denotes moderate risk, and the EPSS indicates a very low exploitation probability (<1%). Exploitation requires an authenticated user account with Author or higher privileges; the attacker must insert malicious code into the alt text and then entice other users to view the affected image or gallery. The vulnerability is not listed in CISA’s KEV catalog, implying no confirmed public exploit yet.

Generated by OpenCVE AI on September 19, 2026 at 20:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the FileBird plugin to the latest available version (6.5.7 or later), which removes the vulnerable alt text handling.
  • Edit or delete any existing image alt text entries that contain suspicious or non‑ASCII characters, replacing them with plain text.
  • If immediate update is not possible, consider temporarily disabling the gallery rendering feature or restricting Author access to media editing until a patch is available.

Generated by OpenCVE AI on September 19, 2026 at 20:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Ninjateam
Ninjateam filebird – Wordpress Media Library Folders & File Manager
Wordpress
Wordpress wordpress
Vendors & Products Ninjateam
Ninjateam filebird – Wordpress Media Library Folders & File Manager
Wordpress
Wordpress wordpress

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alt text in all versions up to, and including, 6.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title FileBird – WordPress Media Library Folders & File Manager <= 6.5.6 - Authenticated (Author+) Stored Cross-Site Scripting
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Ninjateam Filebird – Wordpress Media Library Folders & File Manager
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T14:21:51.720Z

Reserved: 2026-07-07T20:23:28.409Z

Link: CVE-2026-15004

cve-icon Vulnrichment

Updated: 2026-09-19T14:13:41.852Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T08:16:59.730

Modified: 2026-09-19T15:16:58.250

Link: CVE-2026-15004

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:30:21Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')