CVE-2023-0729
- EPSS 0.07%
- Veröffentlicht 09.06.2023 06:15:53
- Zuletzt bearbeitet 21.11.2024 07:37:42
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_sort_order function. This makes it possible for unaut...
CVE-2023-0726
- EPSS 0.07%
- Veröffentlicht 08.02.2023 02:15:08
- Zuletzt bearbeitet 21.11.2024 07:37:42
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_edit_folder function. This makes it possible for unauthent...
CVE-2023-0725
- EPSS 0.07%
- Veröffentlicht 08.02.2023 02:15:08
- Zuletzt bearbeitet 21.11.2024 07:37:42
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_clone_folder function. This makes it possible for unauthen...
CVE-2023-0724
- EPSS 0.07%
- Veröffentlicht 08.02.2023 02:15:08
- Zuletzt bearbeitet 21.11.2024 07:37:42
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_add_folder function. This makes it possible for unauthenti...
CVE-2023-0722
- EPSS 0.07%
- Veröffentlicht 08.02.2023 02:15:08
- Zuletzt bearbeitet 21.11.2024 07:37:41
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_state function. This makes it possible for unauthenti...
CVE-2023-0720
- EPSS 0.05%
- Veröffentlicht 08.02.2023 02:15:08
- Zuletzt bearbeitet 21.11.2024 07:37:41
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_folder_order function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with...
CVE-2023-0717
- EPSS 0.05%
- Veröffentlicht 08.02.2023 02:15:08
- Zuletzt bearbeitet 21.11.2024 07:37:41
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_delete_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with sub...
CVE-2023-0716
- EPSS 0.05%
- Veröffentlicht 08.02.2023 02:15:08
- Zuletzt bearbeitet 21.11.2024 07:37:41
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_edit_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subsc...
CVE-2023-0685
- EPSS 0.07%
- Veröffentlicht 08.02.2023 02:15:07
- Zuletzt bearbeitet 21.11.2024 07:37:37
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_unassign_folders function. This makes it possible for unau...
CVE-2023-0715
- EPSS 0.05%
- Veröffentlicht 08.02.2023 02:15:07
- Zuletzt bearbeitet 21.11.2024 07:37:41
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_clone_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subs...