The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.3 via folder deletion due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with author access or higher, to delete folders created by other users and make their file uploads visible. CVE-2024-35166 may be a duplicate of this issue.
History

Fri, 10 Apr 2026 04:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Apr 2026 17:45:00 +0000

Type Values Removed Values Added
Description The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.3 via folder deletion due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with author access or higher, to delete folders created by other users and make their file uploads visible. The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.3 via folder deletion due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with author access or higher, to delete folders created by other users and make their file uploads visible. CVE-2024-35166 may be a duplicate of this issue.
Title FileBird – WordPress Media Library Folders & File Manager <= 5.6.3 - Authenticated (Author+) Insecure Direct Object Reference

Wed, 23 Apr 2025 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Ninjateam
Ninjateam filebird
Weaknesses CWE-639
CPEs cpe:2.3:a:ninjateam:filebird:*:*:*:*:*:wordpress:*:*
Vendors & Products Ninjateam
Ninjateam filebird

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-05-02T16:52:18.829Z

Updated: 2026-04-08T17:04:02.489Z

Reserved: 2024-03-08T22:28:44.869Z

Link: CVE-2024-2346

cve-icon Vulnrichment

Updated: 2024-08-01T19:11:53.414Z

cve-icon NVD

Status : Modified

Published: 2024-05-02T17:15:16.960

Modified: 2026-04-08T18:21:04.610

Link: CVE-2024-2346

cve-icon Redhat

No data.