Wickedplugins

Wicked Folders

22 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.01%
  • Veröffentlicht 15.03.2026 01:19:05
  • Zuletzt bearbeitet 16.03.2026 14:53:07

The Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via the delete_folders() function due to missing validati...

  • EPSS 0.1%
  • Veröffentlicht 09.06.2023 06:15:53
  • Zuletzt bearbeitet 08.04.2026 19:18:03

The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_sort_order function. This makes it possible for unaut...

  • EPSS 0.09%
  • Veröffentlicht 08.02.2023 02:15:08
  • Zuletzt bearbeitet 08.04.2026 18:17:48

The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_edit_folder function. This makes it possible for unauthent...

  • EPSS 0.09%
  • Veröffentlicht 08.02.2023 02:15:08
  • Zuletzt bearbeitet 08.04.2026 18:17:45

The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_clone_folder function. This makes it possible for unauthen...

  • EPSS 0.09%
  • Veröffentlicht 08.02.2023 02:15:08
  • Zuletzt bearbeitet 08.04.2026 17:16:50

The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_add_folder function. This makes it possible for unauthenti...

  • EPSS 0.09%
  • Veröffentlicht 08.02.2023 02:15:08
  • Zuletzt bearbeitet 08.04.2026 17:16:50

The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_state function. This makes it possible for unauthenti...

  • EPSS 0.16%
  • Veröffentlicht 08.02.2023 02:15:08
  • Zuletzt bearbeitet 08.04.2026 18:17:45

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_folder_order function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with...

  • EPSS 0.16%
  • Veröffentlicht 08.02.2023 02:15:08
  • Zuletzt bearbeitet 08.04.2026 18:17:44

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_delete_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with sub...

  • EPSS 0.16%
  • Veröffentlicht 08.02.2023 02:15:08
  • Zuletzt bearbeitet 08.04.2026 18:17:44

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_edit_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subsc...

  • EPSS 0.16%
  • Veröffentlicht 08.02.2023 02:15:07
  • Zuletzt bearbeitet 08.04.2026 19:18:02

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_state function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscr...