Authorization Vulnerability Affects Filebird
CVE-2023-25966
6.5MEDIUM
What is CVE-2023-25966?
A missing authorization vulnerability exists in the Ninja Team Filebird plugin that could allow unauthorized users to exploit improperly configured access control security levels. This flaw affects versions of Filebird from n/a up to 5.1.4, potentially leading to unauthorized access to sensitive areas of the application, which poses a significant risk for users and administrators relying on this plugin for managing files in WordPress. It is crucial to ensure that appropriate access controls are in place to mitigate potential exploitation.
Affected Version(s)
Filebird <= 5.1.4