Extension WordPress
Vulnérabilités Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types
Cette page rassemble les failles publiées pour Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types
22 fiches
Wicked Folders <= 4.1.0 – Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Folder Deletion
The Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via the delete_folders() function due to missing…
*-4.1.0
4.1.1
14/03/2026
Wicked Folders <= 2.18.16 – Cross-Site Request Forgery on ajax_move_object
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_move_object function. This makes it possible for unauthenticated…
*-2.18.16
2.18.17
07/02/2023
Wicked Folders <= 2.18.16 – Missing Authorization via ajax_save_state
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_state function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions…
*-2.18.16
2.18.17
07/02/2023
Wicked Folders <= 2.18.16 – Missing Authorization on ajax_clone_folder
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_clone_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions…
*-2.18.16
2.18.17
07/02/2023
Wicked Folders <= 2.18.16 – Cross-Site Request Forgery via ajax_save_sort_order
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_sort_order function. This makes it possible for unauthenticated…
*-2.18.16
2.18.17
07/02/2023
Wicked Folders <= 2.18.16 – Missing Authorization on ajax_save_sort_order
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_sort_order function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions…
*-2.18.16
2.18.17
07/02/2023
Wicked Folders <= 2.18.16 – Missing Authorization on ajax_save_folder_order
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_folder_order function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions…
*-2.18.16
2.18.17
07/02/2023
Wicked Folders <= 2.18.16 – Cross-Site Request Forgery via ajax_clone_folder
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_clone_folder function. This makes it possible for unauthenticated…
*-2.18.16
2.18.17
07/02/2023
Wicked Folders <= 2.18.16 – Cross-Site Request Forgery via ajax_delete_folder
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_delete_folder function. This makes it possible for unauthenticated…
*-2.18.16
2.18.17
07/02/2023
Wicked Folders <= 2.18.16 – Cross-Site Request Forgery via ajax_edit_folder
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_edit_folder function. This makes it possible for unauthenticated…
*-2.18.16
2.18.17
07/02/2023
Wicked Folders <= 2.18.16 – Cross-Site Request Forgery on ajax_save_folder
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_folder function. This makes it possible for unauthenticated…
*-2.18.16
2.18.17
07/02/2023
Wicked Folders <= 2.18.16 – Cross-Site Request Forgery via ajax_save_folder_order
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_folder_order function. This makes it possible for unauthenticated…
*-2.18.16
2.18.17
07/02/2023
Wicked Folders <= 2.18.16 – Missing Authorization on ajax_edit_folder
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_edit_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions…
*-2.18.16
2.18.17
07/02/2023
Wicked Folders <= 2.18.16 – Missing Authorization via ajax_delete_folder
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_delete_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions…
*-2.18.16
2.18.17
07/02/2023
Wicked Folders <= 2.18.16 – Missing Authorization on ajax_save_folder
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions…
*-2.18.16
2.18.17
07/02/2023
Wicked Folders <= 2.18.16 – Missing Authorization on ajax_add_folder
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_add_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions…
*-2.18.16
2.18.17
07/02/2023
Wicked Folders <= 2.18.16 – Cross-Site Request Forgery via ajax_save_state
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_state function. This makes it possible for unauthenticated…
*-2.18.16
2.18.17
07/02/2023
Wicked Folders <= 2.18.16 – Missing Authorization on ajax_move_object
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_move_object function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions…
*-2.18.16
2.18.17
07/02/2023
Wicked Folders <= 2.18.16 – Cross-Site Request Forgery via ajax_add_folder
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_add_folder function. This makes it possible for unauthenticated…
*-2.18.16
2.18.17
07/02/2023
Wicked Folders <= 2.18.16 – Cross-Site Request Forgery via ajax_unassign_folders
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_unassign_folders function. This makes it possible for unauthenticated…
*-2.18.16
2.18.17
06/02/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.