PT-2026-1699 · WordPress · Folders – Unlimited Folders To Organize Media Library Folder
CVE-2025-12640
·
Publicado
2026-01-08
·
Atualizado
2026-01-08
CVSS v3.1
4.3
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress versions up to and including 3.1.5
Description
The Folders plugin for WordPress is susceptible to unauthorized arbitrary media replacement. This occurs because of a lack of proper object-level authorization checks within the
handle folders file upload() function. Authenticated attackers possessing Author-level access or higher can exploit this to replace any media file within the WordPress Media Library.Recommendations
Versions prior to and including 3.1.5 should be updated to a newer, fixed version of the plugin. As a temporary workaround, consider restricting access to the
handle folders file upload() function for users with Author-level access or below.Correção
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Folders – Unlimited Folders To Organize Media Library Folder