Impact
The plugin contains a misconfigured capability check in the wcp_change_post_folder function that allows authenticated users with Contributor-level privileges or higher to move any folder content to any other folder. This flaw gives attackers the ability to reorganize, hide, or replace content within the media library, pages, or posts, potentially leading to defacement or loss of data integrity. The vulnerability stems from an access control weakness (CWE-863).
Affected Systems
WordPress sites running the Premio Folders plugin, versions up to and including 3.1.5. The issue is present in every release up to that version, regardless of minor patch level.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The EPSS score is under 1%, suggesting a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers need to be authenticated as a Contributor or higher role, so the exploit requires legitimate access to the WordPress administration console.
OpenCVE Enrichment