CVE-2025-12640

MEDIUM

Folders - Unlimited Folders to Organize Media Library Folder, Pages...

Title source: llm
STIX 2.1

Description

The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vulnerable to Unauthorized Arbitrary Media Replacement in all versions up to, and including, 3.1.5. This is due to missing object-level authorization checks in the handle_folders_file_upload() function. This makes it possible for authenticated attackers, with Author-level access and above, to replace arbitrary media files from the WordPress Media Library.

Scores

CVSS v3 4.3
EPSS 0.0016
EPSS Percentile 5.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (2)
galdub/Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager < 3.1.5
premio/Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager < 3.1.5
Published Jan 08, 2026
Tracked Since Feb 18, 2026