CVE Database /
CVE-2025-12640
CVE · Medium
CVE-2025-12640 — Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager [folders] < 3.1.6
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-12640
|
Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager [folders] < 3.1.6 |
Missing Authorization |
Medium
4.3
|
< 3.1.6
|
3.1.6 |
2026-01-07 |
—
|
CVE-2025-12640
The Folders plugin for WordPress contains a security flaw that allows authorized users with elevated permissions to swap out any media file within the site's library without proper clearance. This issue arises from inadequate checks in the handle_folders_file_upload() function, which fails to verify user access rights on a per-object basis. As a result, malicious actors can exploit this vulnerability by uploading unauthorized files under the guise of legitimate users with Author-level or higher privileges.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings