MEDIUM
Folders <= 3.1.5 - Incorrect Authorization to Authenticated (Contributor+) Folder Content Manipulation
Published Nov 27, 2025
4.3
MEDIUMCVSS 3.1
EPSS 0.23%
Description
The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a misconfigured capability check on the 'wcp_change_post_folder' function in all versions up to, and including, 3.1.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to move arbitrary folder contents to arbitrary folders.
Affected products
-
- Version 0StatusaffectedConstraints<=3.1.5
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Premio | n/a | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://plugins.trac.wordpress.org/browser/folders/trunk/includes/folders.class.php#L3291
- https://plugins.trac.wordpress.org/changeset/3402986/
- https://research.cleantalk.org/cve-2025-12971/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/f3845071-8419-4bb2-b22d-f9ae22fb7d6a?source=cve
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Wordfence
Published Nov 27, 2025
Updated Apr 8, 2026
Reserved Nov 10, 2025
Link CVE-2025-12971
CISA Vulnrichment
Updated Dec 3, 2025