Folders WordPress Plugin Missing Authorization Vulnerability Allows Arbitrary Media Replacement

Vulnerability

A vulnerability exists in the Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress, affecting all versions through 3.1.5. The issue arises from a lack of object-level authorization checks in the handle_folders_file_upload() function, enabling authenticated attackers with Author-level access or higher to replace arbitrary media files in the WordPress Media Library.

Impact

Exploitation of this vulnerability allows for unauthorized replacement of media files in the WordPress Media Library, potentially leading to misuse of media assets or disruption of content.

Remediation

Users are advised to update the Folders WordPress plugin to version 3.1.6 or a newer patched version.

Added: Jan 8, 2026, 3:18 AM
Updated: Jan 8, 2026, 3:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
5.9
remediation
7.7
relevance
1.9
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.