CVE · Medium

CVE-2025-12640 — Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager [folders] < 3.1.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-12640 Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager [folders] < 3.1.6 Missing Authorization Medium 4.3 < 3.1.6 3.1.6 2026-01-07

CVE-2025-12640

The Folders plugin for WordPress contains a security flaw that allows authorized users with elevated permissions to swap out any media file within the site's library without proper clearance. This issue arises from inadequate checks in the handle_folders_file_upload() function, which fails to verify user access rights on a per-object basis. As a result, malicious actors can exploit this vulnerability by uploading unauthorized files under the guise of legitimate users with Author-level or higher privileges.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.