Wickedplugins
Wickedplugins Wicked Folders: vulnerabilidades y CVE
Wickedplugins Wicked Folders tiene 22 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE22
Últimos 12 meses1
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-1883 | Media (4.3) | 0.23% | — | 16 mar 2026 | The Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via the delete_folders()… |
| CVE-2023-0729 | Media (4.3) | 0.29% | — | 9 jun 2023 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_sort_order function.… |
| CVE-2023-0726 | Media (4.3) | 0.31% | — | 8 feb 2023 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_edit_folder function. This… |
| CVE-2023-0725 | Media (4.3) | 0.31% | — | 8 feb 2023 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_clone_folder function. This… |
| CVE-2023-0724 | Media (4.3) | 0.31% | — | 8 feb 2023 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_add_folder function. This… |
| CVE-2023-0722 | Media (4.3) | 0.31% | — | 8 feb 2023 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_state function. This… |
| CVE-2023-0720 | Media (4.3) | 0.58% | — | 8 feb 2023 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_folder_order function in versions up to, and including, 2.18.16. This makes it possible… |
| CVE-2023-0717 | Media (4.3) | 0.58% | — | 8 feb 2023 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_delete_folder function in versions up to, and including, 2.18.16. This makes it possible for… |
| CVE-2023-0716 | Media (4.3) | 0.58% | — | 8 feb 2023 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_edit_folder function in versions up to, and including, 2.18.16. This makes it possible for… |
| CVE-2023-0715 | Media (4.3) | 0.58% | — | 8 feb 2023 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_clone_folder function in versions up to, and including, 2.18.16. This makes it possible for… |
| CVE-2023-0711 | Media (4.3) | 0.58% | — | 8 feb 2023 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_state function in versions up to, and including, 2.18.16. This makes it possible for… |
| CVE-2023-0685 | Media (4.3) | 0.31% | — | 8 feb 2023 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_unassign_folders function.… |
| CVE-2023-0684 | Media (4.3) | 0.58% | — | 8 feb 2023 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_unassign_folders function in versions up to, and including, 2.18.16. This makes it possible for… |
| CVE-2023-0718 | Media (4.3) | 0.59% | — | 8 feb 2023 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_folder function in versions up to, and including, 2.18.16. This makes it possible for… |
| CVE-2023-0730 | Media (4.3) | 0.32% | — | 7 feb 2023 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_folder_order function.… |
| CVE-2023-0727 | Media (4.3) | 0.32% | — | 7 feb 2023 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_delete_folder function.… |
| CVE-2023-0723 | Media (4.3) | 0.32% | — | 7 feb 2023 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_move_object function. This… |
| CVE-2023-0719 | Media (4.3) | 0.60% | — | 7 feb 2023 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_sort_order function in versions up to, and including, 2.18.16. This makes it possible for… |
| CVE-2023-0712 | Media (4.3) | 0.60% | — | 7 feb 2023 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_move_object function in versions up to, and including, 2.18.16. This makes it possible for… |
| CVE-2023-0728 | Media (4.3) | 0.31% | — | 7 feb 2023 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_folder function. This… |
| CVE-2023-0713 | Media (4.3) | 0.58% | — | 7 feb 2023 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_add_folder function in versions up to, and including, 2.18.16. This makes it possible for… |
| CVE-2021-24919 | Alta (8.8) | 1.5% | — | 1 feb 2022 | The Wicked Folders WordPress plugin before 2.8.10 does not sanitise and escape the folder_id parameter before using it in a SQL statement in the wicked_folders_save_sort_order AJAX action, available to any authenticated… |