Extension WordPress

Vulnérabilités Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types

Cette page rassemble les failles publiées pour Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types, leurs plages de versions affectées et les correctifs signalés dans la base locale.

22Vulnérabilités
0Critiques
22Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types

22 fiches

CVE-2026-1883 Moyenne · 4,3
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types

Wicked Folders <= 4.1.0 – Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Folder Deletion

The Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via the delete_folders() function due to missing…

Versions affectées

*-4.1.0

Correctif

4.1.1

Publication

14/03/2026

CVE-2023-0723 Moyenne · 5,4
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types

Wicked Folders <= 2.18.16 – Cross-Site Request Forgery on ajax_move_object

The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_move_object function. This makes it possible for unauthenticated…

Versions affectées

*-2.18.16

Correctif

2.18.17

Publication

07/02/2023

CVE-2023-0711 Moyenne · 5,4
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types

Wicked Folders <= 2.18.16 – Missing Authorization via ajax_save_state

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_state function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions…

Versions affectées

*-2.18.16

Correctif

2.18.17

Publication

07/02/2023

CVE-2023-0715 Moyenne · 5,4
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types

Wicked Folders <= 2.18.16 – Missing Authorization on ajax_clone_folder

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_clone_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions…

Versions affectées

*-2.18.16

Correctif

2.18.17

Publication

07/02/2023

CVE-2023-0729 Moyenne · 5,4
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types

Wicked Folders <= 2.18.16 – Cross-Site Request Forgery via ajax_save_sort_order

The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_sort_order function. This makes it possible for unauthenticated…

Versions affectées

*-2.18.16

Correctif

2.18.17

Publication

07/02/2023

CVE-2023-0719 Moyenne · 5,4
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types

Wicked Folders <= 2.18.16 – Missing Authorization on ajax_save_sort_order

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_sort_order function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions…

Versions affectées

*-2.18.16

Correctif

2.18.17

Publication

07/02/2023

CVE-2023-0720 Moyenne · 5,4
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types

Wicked Folders <= 2.18.16 – Missing Authorization on ajax_save_folder_order

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_folder_order function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions…

Versions affectées

*-2.18.16

Correctif

2.18.17

Publication

07/02/2023

CVE-2023-0725 Moyenne · 5,4
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types

Wicked Folders <= 2.18.16 – Cross-Site Request Forgery via ajax_clone_folder

The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_clone_folder function. This makes it possible for unauthenticated…

Versions affectées

*-2.18.16

Correctif

2.18.17

Publication

07/02/2023

CVE-2023-0727 Moyenne · 5,4
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types

Wicked Folders <= 2.18.16 – Cross-Site Request Forgery via ajax_delete_folder

The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_delete_folder function. This makes it possible for unauthenticated…

Versions affectées

*-2.18.16

Correctif

2.18.17

Publication

07/02/2023

CVE-2023-0726 Moyenne · 5,4
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types

Wicked Folders <= 2.18.16 – Cross-Site Request Forgery via ajax_edit_folder

The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_edit_folder function. This makes it possible for unauthenticated…

Versions affectées

*-2.18.16

Correctif

2.18.17

Publication

07/02/2023

CVE-2023-0728 Moyenne · 5,4
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types

Wicked Folders <= 2.18.16 – Cross-Site Request Forgery on ajax_save_folder

The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_folder function. This makes it possible for unauthenticated…

Versions affectées

*-2.18.16

Correctif

2.18.17

Publication

07/02/2023

CVE-2023-0730 Moyenne · 5,4
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types

Wicked Folders <= 2.18.16 – Cross-Site Request Forgery via ajax_save_folder_order

The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_folder_order function. This makes it possible for unauthenticated…

Versions affectées

*-2.18.16

Correctif

2.18.17

Publication

07/02/2023

CVE-2023-0716 Moyenne · 5,4
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types

Wicked Folders <= 2.18.16 – Missing Authorization on ajax_edit_folder

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_edit_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions…

Versions affectées

*-2.18.16

Correctif

2.18.17

Publication

07/02/2023

CVE-2023-0717 Moyenne · 5,4
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types

Wicked Folders <= 2.18.16 – Missing Authorization via ajax_delete_folder

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_delete_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions…

Versions affectées

*-2.18.16

Correctif

2.18.17

Publication

07/02/2023

CVE-2023-0718 Moyenne · 5,4
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types

Wicked Folders <= 2.18.16 – Missing Authorization on ajax_save_folder

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions…

Versions affectées

*-2.18.16

Correctif

2.18.17

Publication

07/02/2023

CVE-2023-0713 Moyenne · 5,4
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types

Wicked Folders <= 2.18.16 – Missing Authorization on ajax_add_folder

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_add_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions…

Versions affectées

*-2.18.16

Correctif

2.18.17

Publication

07/02/2023

CVE-2023-0722 Moyenne · 5,4
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types

Wicked Folders <= 2.18.16 – Cross-Site Request Forgery via ajax_save_state

The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_state function. This makes it possible for unauthenticated…

Versions affectées

*-2.18.16

Correctif

2.18.17

Publication

07/02/2023

CVE-2023-0712 Moyenne · 5,4
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types

Wicked Folders <= 2.18.16 – Missing Authorization on ajax_move_object

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_move_object function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions…

Versions affectées

*-2.18.16

Correctif

2.18.17

Publication

07/02/2023

CVE-2023-0724 Moyenne · 5,4
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types

Wicked Folders <= 2.18.16 – Cross-Site Request Forgery via ajax_add_folder

The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_add_folder function. This makes it possible for unauthenticated…

Versions affectées

*-2.18.16

Correctif

2.18.17

Publication

07/02/2023

CVE-2023-0685 Moyenne · 5,4
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types

Wicked Folders <= 2.18.16 – Cross-Site Request Forgery via ajax_unassign_folders

The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_unassign_folders function. This makes it possible for unauthenticated…

Versions affectées

*-2.18.16

Correctif

2.18.17

Publication

06/02/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités