CVE-2025-12640 describes an Unauthorized Arbitrary Media Replacement vulnerability in the Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager WordPress plugin, affecting all versions up to and including 3.1.5. This flaw stems from missing object-level authorization, allowing authenticated attackers with Author-level access or higher to replace any media file in the WordPress Media Library. Rated as Medium severity (CVSS 4.3), the vulnerability has a low attack complexity and requires user authentication, but does not appear to be actively exploited, nor is public exploit code or significant community discussion currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Premio | Folders – Unlimited Folders To Organize Media Library Folder, Pages, Posts, File Manager | >= 0, <= 3.1.5CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.