SQL Injection Vulnerability in FileBird Media Library Plugin for WordPress
CVE-2025-6986
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 6 August 2025
What is CVE-2025-6986?
The FileBird – WordPress Media Library Folders & File Manager plugin is susceptible to SQL Injection attacks through the 'search' parameter. This issue affects all versions up to and including 6.4.8, resulting from inadequate escaping of user-supplied input and poor preparation of existing SQL queries. Exploitation of this flaw allows authenticated users with Author-level access or higher to manipulate SQL queries to extract sensitive data from the database, exposing potentially critical information.
Affected Version(s)
FileBird – WordPress Media Library Folders & File Manager * <= 6.4.8