CVE-2026-1883
- EPSS 0.01%
- Veröffentlicht 15.03.2026 01:19:05
- Zuletzt bearbeitet 16.03.2026 14:53:07
The Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via the delete_folders() function due to missing validati...
CVE-2023-0729
- EPSS 0.1%
- Veröffentlicht 09.06.2023 06:15:53
- Zuletzt bearbeitet 08.04.2026 19:18:03
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_sort_order function. This makes it possible for unaut...
CVE-2023-0726
- EPSS 0.09%
- Veröffentlicht 08.02.2023 02:15:08
- Zuletzt bearbeitet 08.04.2026 18:17:48
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_edit_folder function. This makes it possible for unauthent...
CVE-2023-0725
- EPSS 0.09%
- Veröffentlicht 08.02.2023 02:15:08
- Zuletzt bearbeitet 08.04.2026 18:17:45
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_clone_folder function. This makes it possible for unauthen...
CVE-2023-0724
- EPSS 0.09%
- Veröffentlicht 08.02.2023 02:15:08
- Zuletzt bearbeitet 08.04.2026 17:16:50
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_add_folder function. This makes it possible for unauthenti...
CVE-2023-0722
- EPSS 0.09%
- Veröffentlicht 08.02.2023 02:15:08
- Zuletzt bearbeitet 08.04.2026 17:16:50
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_state function. This makes it possible for unauthenti...
CVE-2023-0720
- EPSS 0.16%
- Veröffentlicht 08.02.2023 02:15:08
- Zuletzt bearbeitet 08.04.2026 18:17:45
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_folder_order function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with...
CVE-2023-0717
- EPSS 0.16%
- Veröffentlicht 08.02.2023 02:15:08
- Zuletzt bearbeitet 08.04.2026 18:17:44
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_delete_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with sub...
CVE-2023-0716
- EPSS 0.16%
- Veröffentlicht 08.02.2023 02:15:08
- Zuletzt bearbeitet 08.04.2026 18:17:44
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_edit_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subsc...
CVE-2023-0711
- EPSS 0.16%
- Veröffentlicht 08.02.2023 02:15:07
- Zuletzt bearbeitet 08.04.2026 19:18:02
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_state function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscr...