Folders WordPress Plugin Missing Authorization Vulnerability Allows Arbitrary Media Replacement
Vulnerability
A vulnerability exists in the Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress, affecting all versions through 3.1.5. The issue arises from a lack of object-level authorization checks in the handle_folders_file_upload() function, enabling authenticated attackers with Author-level access or higher to replace arbitrary media files in the WordPress Media Library.
Impact
Exploitation of this vulnerability allows for unauthorized replacement of media files in the WordPress Media Library, potentially leading to misuse of media assets or disruption of content.
Remediation
Users are advised to update the Folders WordPress plugin to version 3.1.6 or a newer patched version.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
