Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 08 Jan 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Jan 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Galdub
Galdub folders Wordpress Wordpress wordpress |
|
| Vendors & Products |
Galdub
Galdub folders Wordpress Wordpress wordpress |
Thu, 08 Jan 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vulnerable to Unauthorized Arbitrary Media Replacement in all versions up to, and including, 3.1.5. This is due to missing object-level authorization checks in the handle_folders_file_upload() function. This makes it possible for authenticated attackers, with Author-level access and above, to replace arbitrary media files from the WordPress Media Library. | |
| Title | Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager <= 3.1.5 - Missing Authorization to Authenticated (Author+) Media Replacement | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-01-08T16:20:05.877Z
Reserved: 2025-11-03T18:46:34.428Z
Link: CVE-2025-12640
Updated: 2026-01-08T16:20:01.092Z
Status : Awaiting Analysis
Published: 2026-01-08T03:15:42.873
Modified: 2026-01-08T18:08:18.457
Link: CVE-2025-12640
No data.
OpenCVE Enrichment
Updated: 2026-01-08T09:47:46Z