Junglewise Threat Intelligence

CVE-2026-15004: FileBird stored cross-site scripting via image alt text

CVE-2026-15004 · Severity: medium · CVSS 5.4 · Published 2026-09-18

Executive brief

FileBird is a popular WordPress plugin that organizes media files and images in the WordPress admin interface. An authenticated attacker with Author-level privileges can inject malicious scripts via image alt text fields, which then execute when other users view affected pages, potentially compromising user sessions or stealing sensitive information.

Technical details

The FileBird WordPress plugin is vulnerable to stored cross-site scripting (XSS) through insufficient input sanitization and output escaping of image alt text attributes. An authenticated attacker with Author-level or higher permissions can inject arbitrary JavaScript payloads via the alt text field during image upload or editing. The vulnerability persists in stored form and executes in the browsers of any user who accesses a page containing the malicious image, allowing attackers to steal session tokens, redirect users, or perform actions on their behalf. The vulnerability affects versions up to and including 6.5.6 of the plugin.

Affected products

  • FileBird FileBird up to and including 6.5.6

Timeline

  • 2026-09-18: disclosed

References