CVE-2025-14632 - Filr – Secure document library <= 1.2.11 - authenticated (administrator+) stored...

CVE-2025-14632 - Filr – Secure document library <= 1.2.11 - authenticated (administrator+) stored...

CVE ID : CVE-2025-14632 Published : Jan. 17, 2026, 3:16 a.m. | 1 hour, 9 minutes ago Description : The Filr – Secure document library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via unrestricted file upload in all versions up to, and including, 1.2.11 due to insufficient file type restrictions in the FILR_Uploader class. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload malicious HTML files containing JavaScript that will execute whenever a user accesses the uploaded file, granted they have permission to create or edit posts with the 'filr' post type. Severity: 4.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
Jan. 17, 2026
Affected Product: WordPress