Description

The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vulnerable to Unauthorized Arbitrary Media Replacement in all versions up to, and including, 3.1.5. This is due to missing object-level authorization checks in the handle_folders_file_upload() function. This makes it possible for authenticated attackers, with Author-level access and above, to replace arbitrary media files from the WordPress Media Library.

INFO

Published Date :

2026-01-08T02:21:16.994Z

Last Modified :

2026-01-08T16:20:05.877Z

Source :

Wordfence
AFFECTED PRODUCTS

The following products are affected by CVE-2025-12640 vulnerability.

Vendors Products
Galdub
  • Folders
Wordpress
  • Wordpress

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact