Filestack Security & Risk Analysis

wordpress.org/plugins/filepicker-media-uploader

Use Filestack to upload files directly from Facebook, Instagram, Google Images and more for your WordPress site, without ever leaving WordPress.

20 active installs v2.0.8 PHP + WP 3.0.1+ Updated Nov 21, 2016
filestack-filepicker-filepicker-io-media-uploads-facebook-dropbox-google-drive-box-skydrive-instagram-picasa-instagram-flickr-github-evernote-alfresco
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEFeb 17, 2026
Download
Safety Verdict

Is Filestack Safe to Use in 2026?

Use With Caution

Score 63/100

Filestack has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Feb 17, 2026Updated 9yr ago
Risk Assessment

The static analysis of filepicker-media-uploader v2.0.8 reveals an exceptionally clean codebase, with no identified dangerous functions, SQL injection vulnerabilities, unescaped output, file operations, or external HTTP requests. The absence of any identified taint flows further reinforces this positive picture, indicating that data handled by the plugin is likely processed securely. Furthermore, the plugin boasts zero entry points that lack authentication checks and no shortcodes, cron events, or REST API routes that bypass permission callbacks, which is a strong indicator of good security design.

However, the plugin's vulnerability history presents a significant concern. The presence of one unpatched medium-severity CVE, specifically related to Cross-site Scripting (XSS), overshadows the otherwise robust static analysis. This indicates a potential for attackers to exploit this known flaw to inject malicious scripts, leading to compromised user sessions or data theft. The recency of this last vulnerability further underscores the immediate need for attention.

In conclusion, while filepicker-media-uploader v2.0.8 demonstrates excellent secure coding practices in its static analysis, the existence of an unpatched XSS vulnerability is a critical weakness that poses a real risk to users. The plugin's strengths lie in its secure handling of data and limited attack surface, but the unpatched vulnerability necessitates immediate action to mitigate potential exploitation.

Key Concerns

  • Unpatched medium severity CVE
Vulnerabilities
1

Filestack Security Vulnerabilities

CVEs by Year

1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-13959medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Filestack <= 2.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

Feb 17, 2026Unpatched
Code Analysis
Analyzed Mar 16, 2026

Filestack Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Filestack Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Filestack Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedNov 21, 2016
PHP min version
Downloads4K

Community Trust

Rating80/100
Number of ratings3
Active installs20
Alternatives

Filestack Alternatives

No alternatives data available yet.

Developer Profile

Filestack Developer Profile

shanaver

2 plugins · 40 total installs

69
trust score
Avg Security Score
64/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Filestack

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/filepicker-media-uploader/css/style.css/wp-content/plugins/filepicker-media-uploader/css/wp_media.css/wp-content/plugins/filepicker-media-uploader/js/filepicker.js/wp-content/plugins/filepicker-media-uploader/js/filepicker_wp_media.js/wp-content/plugins/filepicker-media-uploader/js/jquery.filepicker.js
Script Paths
/wp-content/plugins/filepicker-media-uploader/js/filepicker.js/wp-content/plugins/filepicker-media-uploader/js/filepicker_wp_media.js/wp-content/plugins/filepicker-media-uploader/js/jquery.filepicker.js
Version Parameters
filepicker-media-uploader/css/style.css?ver=filepicker-media-uploader/css/wp_media.css?ver=filepicker-media-uploader/js/filepicker.js?ver=filepicker-media-uploader/js/filepicker_wp_media.js?ver=filepicker-media-uploader/js/jquery.filepicker.js?ver=

HTML / DOM Fingerprints

CSS Classes
filepicker-upload-buttonfilepicker-media-upload-formfilepicker-media-previewfilepicker-media-input
Data Attributes
data-fp-apikeydata-fp-button-textdata-fp-button-classdata-fp-containerdata-fp-multi-selectdata-fp-modal+16 more
JS Globals
window.Filepicker
REST Endpoints
/wp-json/filepicker/v1/upload
Shortcode Output
[filepicker]
FAQ

Frequently Asked Questions about Filestack