Brandfolder – Digital Asset Management Simplified.
Brandfolder – Digital Asset Management Simplified. has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2016 and 2026; 2 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 8.1, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 1 high.
The most common weakness is PHP Remote File Inclusion, behind 2 of the records (67%). Other recurring categories include Cross-Site Scripting.
2 of the records (67%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2026.
2 independent researchers contributed these findings, most of them (2) reported by AMAR^SHG. Brandfolder – Digital Asset Management Simplified. is installed on roughly 60 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.4.10.
CVE-2016-20080Brandfolder – Digital Asset Management Simplified. <= 3.0 - Unauthenticated Local File Inclusion
Read the full analysisVulnerability Records

Brandfolder – Digital Asset Management Simplified.
Author
Brandfolder
This plugin requires a Brandfolder account which you can setup at Brandfolder.com This plugin provides one block and is only compatible with the Gutenberg editor at this time. Features of the Brandfolder WordPress plugin Edit your Brandfolders directly from your WordPress admin panel. Easily embed your Brandfolder using our Popup Embed on any widget, menu bar, page, or post. The Brandfolder integration allows you to quickly grab assets from your Brandfolders to be used in Pages/Posts. Use the [Brandfolder] shortcode in either widgets, pages, or posts to quickly create a Popup Embed link: [Brandfolder id="mapmyfitness" collection="mapmyrun" query="" text="View our Brandfolder" classes="brandfolder"] Read all about the different embed options on the Brandfolder Knowledge Base. Support Visit https://help.smartsheet.com/brandfolder for support & documentation. We also recommend the WordPress Support for extended help. External services This plugin connects to external Brandfolder services to provide digital asset management functionality. The plugin communicates with the following external services: Brandfolder CDN and API Services * Service: Brandfolder’s content delivery network and API services * Purpose: To load the Brandfolder JavaScript library, display assets, and enable asset selection functionality * Data sent: When users interact with Brandfolder embeds or select assets, the plugin may send: – Brandfolder account identifiers – Collection and asset query parameters – User interaction data for asset selection * When data is sent: Data is transmitted when: – The Brandfolder embed is loaded on a page – Users click on Brandfolder links or buttons – Assets are selected or embedded from Brandfolder * External domains used: – cdn.brandfolder.com – For loading the Brandfolder JavaScript library – integration-panel-ui.brandfolder-svc.com – For the asset selection interface – brandfolder.com – For direct links to Brandfolder collections Legal Information: * Brandfolder Terms of Service: https://brandfolder.com/terms-of-service * Brandfolder Privacy Policy: https://brandfolder.com/privacy-policy By using this plugin, you acknowledge that your website will connect to these external Brandfolder services. Please ensure this complies with your website’s privacy policy and terms of service.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C