
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-12640 is an unauthorized arbitrary media replacement vulnerability in the "Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager" plugin for WordPress. It affects all versions up to and including 3.1.5, and was disclosed on January 7–8, 2026, with the fix released in version 3.1.6. The vulnerability was reported by Wordfence and carries a CVSS v3.1 base score of 4.3 (Medium) (Wordfence).
The root cause is a missing object-level authorization check (CWE-862) in the handle_folders_file_upload() function within the plugin's media.replace.php file. Because the function does not verify whether the authenticated user has permission to modify a specific media file, any user with Author-level access or higher can supply an arbitrary media file ID and replace its content with a file of their choosing. The fix was introduced in version 3.1.6, as visible in the plugin's SVN changeset (WordPress Plugin Changeset, Wordfence).
Successful exploitation allows an authenticated attacker with Author-level privileges or above to overwrite any media file in the WordPress Media Library, regardless of ownership. This primarily affects integrity — an attacker could replace images, documents, or other media assets site-wide with malicious or defaced content, potentially impacting site reputation and user trust. There is no direct confidentiality or availability impact based on the current CVSS assessment (Wordfence).
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.026% (0.000260), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access at the Author level or above, which limits the attack surface compared to unauthenticated vulnerabilities (Wordfence).
handle_folders_file_upload(), supplying the target media file's ID and a replacement file (e.g., a defaced image or malicious document) without the function enforcing ownership checks.handle_folders_file_upload) from Author-level or higher accounts targeting media IDs they do not own; unexpected media replacement activity in WordPress audit logs.wp-content/uploads/ with recently modified timestamps that do not correspond to expected editorial activity; file content mismatches (e.g., images replaced with unexpected file types or content).Update the Folders plugin to version 3.1.6 or later, which introduces proper object-level authorization checks in the handle_folders_file_upload() function. No configuration-based workaround is available; upgrading is the only effective remediation. Site administrators should also audit the Media Library for unexpected file replacements and review Author-level user accounts for signs of compromise (WordPress Plugin Changeset, Wordfence).
Sucuri included this vulnerability in their January 2026 vulnerability patch roundup, recommending WordPress site owners update affected plugins promptly (Sucuri Blog). No significant broader media coverage or notable researcher commentary beyond standard vulnerability disclosure channels has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."