CVE-2025-12640
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-12640 is an unauthorized arbitrary media replacement vulnerability in the "Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager" plugin for WordPress. It affects all versions up to and including 3.1.5, and was disclosed on January 7–8, 2026, with the fix released in version 3.1.6. The vulnerability was reported by Wordfence and carries a CVSS v3.1 base score of 4.3 (Medium) (Wordfence).

Technical details

The root cause is a missing object-level authorization check (CWE-862) in the handle_folders_file_upload() function within the plugin's media.replace.php file. Because the function does not verify whether the authenticated user has permission to modify a specific media file, any user with Author-level access or higher can supply an arbitrary media file ID and replace its content with a file of their choosing. The fix was introduced in version 3.1.6, as visible in the plugin's SVN changeset (WordPress Plugin Changeset, Wordfence).

Impact

Successful exploitation allows an authenticated attacker with Author-level privileges or above to overwrite any media file in the WordPress Media Library, regardless of ownership. This primarily affects integrity — an attacker could replace images, documents, or other media assets site-wide with malicious or defaced content, potentially impacting site reputation and user trust. There is no direct confidentiality or availability impact based on the current CVSS assessment (Wordfence).

Exploitability

No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.026% (0.000260), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access at the Author level or above, which limits the attack surface compared to unauthenticated vulnerabilities (Wordfence).

Exploitation steps

  1. Gain authenticated access: Obtain or compromise a WordPress account with at least Author-level privileges on the target site running the Folders plugin ≤ 3.1.5.
  2. Identify target media file: Browse the WordPress Media Library or enumerate media file IDs via the WordPress REST API or admin interface to identify a target media asset to replace.
  3. Craft malicious upload request: Send a crafted HTTP POST request to the endpoint handled by handle_folders_file_upload(), supplying the target media file's ID and a replacement file (e.g., a defaced image or malicious document) without the function enforcing ownership checks.
  4. Confirm replacement: Verify that the target media file has been replaced site-wide by accessing the original media URL, which now serves the attacker-supplied content (Wordfence).

Indicators of compromise

  • Logs: WordPress access logs showing POST requests to the Folders plugin's file upload handler (handle_folders_file_upload) from Author-level or higher accounts targeting media IDs they do not own; unexpected media replacement activity in WordPress audit logs.
  • File System: Media files in wp-content/uploads/ with recently modified timestamps that do not correspond to expected editorial activity; file content mismatches (e.g., images replaced with unexpected file types or content).
  • Application: WordPress Media Library entries showing ownership or content changes inconsistent with the listed author; media files serving unexpected or defaced content when accessed via their public URLs.

Mitigation and workarounds

Update the Folders plugin to version 3.1.6 or later, which introduces proper object-level authorization checks in the handle_folders_file_upload() function. No configuration-based workaround is available; upgrading is the only effective remediation. Site administrators should also audit the Media Library for unexpected file replacements and review Author-level user accounts for signs of compromise (WordPress Plugin Changeset, Wordfence).

Community reactions

Sucuri included this vulnerability in their January 2026 vulnerability patch roundup, recommending WordPress site owners update affected plugins promptly (Sucuri Blog). No significant broader media coverage or notable researcher commentary beyond standard vulnerability disclosure channels has been identified.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-15413CRITICAL10
  • link-factory
NoNoAug 13, 2026
CVE-2026-18146HIGH7.2
  • fluentform
NoYesAug 13, 2026
CVE-2026-3639MEDIUM6.4
  • password-protect-page
NoNoAug 13, 2026
CVE-2026-14332MEDIUM5.4
  • ecwid-shopping-cart
NoYesAug 13, 2026
CVE-2026-3835MEDIUM5.3
  • prevent-direct-access
NoYesAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management