---
id: CVE-2025-12900
title: >-
  The FileBird – WordPress Media Library Folders & File Manager plugin for
  WordPress is vulnerable to missing authorization in all versions up to, and
  including, 6.5.1 via the "ConvertController::insertToNewTable" function due to
  missing v…
summary: >-
  The FileBird – WordPress Media Library Folders & File Manager plugin for
  WordPress is vulnerable to missing authorization in all versions up to, and
  including, 6.5.1 via the "ConvertController::insertToNewTable" function due to
  missing v…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-862
published: '2025-12-15'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T19:10:00.160'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-12900'
references:
  - url: 'https://plugins.trac.wordpress.org/changeset/3411587'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/59592b27-d431-499a-b3c3-3d43a5513c36?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00234
epssPercentile: 0.13127
ingestedAt: '2026-10-07T19:44:15.685Z'
---

## Overview

The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to missing authorization in all versions up to, and including, 6.5.1 via the "ConvertController::insertToNewTable" function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with author level access and above, to inject global folders and reassign arbitrary media attachments to those folders under certain circumstances.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
