Stored Cross-Site Scripting Vulnerability in FileBird Plugin for WordPress
CVE-2024-0691
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 5 February 2024
Summary
The FileBird plugin for WordPress contains a vulnerability that allows authenticated attackers with administrator privileges to perform Stored Cross-Site Scripting (XSS) attacks. This exploit is made possible due to insufficient input sanitization and output escaping when importing folder titles. As a result, attackers can inject arbitrary scripts that may execute whenever a user accesses the compromised page, potentially leading to unauthorized actions or data exposure. Additionally, attackers might use social engineering tactics to trick an administrator into uploading a malicious folder import that could further exploit this vulnerability.
Affected Version(s)
FileBird – WordPress Media Library Folders & File Manager * <= 5.6.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved