Impact
The FileBird plugin allows users to attach image alt text, which is stored without proper sanitization or escaping. This oversight permits authenticated users with Author-level permissions or higher to embed arbitrary JavaScript. The resulting stored cross‑site scripting can execute in the browsers of other site visitors, enabling session hijacking, data theft, or defacement.
Affected Systems
Affecting installations of the FileBird WordPress plugin up to and including version 6.5.6. The vulnerability exists in the image handling and gallery rendering modules, as referenced in the plugin source. WordPress sites running any of these versions are exposed.
Risk and Exploitability
The CVSS score of 5.4 denotes moderate risk, and the EPSS indicates a very low exploitation probability (<1%). Exploitation requires an authenticated user account with Author or higher privileges; the attacker must insert malicious code into the alt text and then entice other users to view the affected image or gallery. The vulnerability is not listed in CISA’s KEV catalog, implying no confirmed public exploit yet.
OpenCVE Enrichment