CVE-2025-11510Medium· 4.3▾ SunlitThe FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /filebird/v1/fb-wipe-clear-all-data function in all versions u…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /filebird/v1/fb-wipe-clear-all-data function in all versions up to, and including, 6.4.9. This makes it possible for authenticated attackers, with author-level access and above, to reset all of the plugin's configuration data.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-11050Medium· 6.3A flaw has been found in Portabilis i-Educar up to 2.10
CVE-2025-11049Medium· 6.3A vulnerability was detected in Portabilis i-Educar up to 2.10
CVE-2025-11047Medium· 6.3A weakness has been identified in Portabilis i-Educar up to 2.10
CVE-2025-11048Medium· 6.3A security vulnerability has been detected in Portabilis i-Educar up to 2.10
CVE-2025-11030High· 7.3A vulnerability was detected in Tutorials-Website Employee Management System up to 611887d8f8375271ce8abc704507d46340837a60
CVE-2026-11930Medium· 5.9IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 may not enforce authorization correctly for some web servers.