CVE-2023-0728
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2023-0715
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_clone_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2023-0711
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_state function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the view state of the folder structure maintained by the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2023-0719
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_sort_order function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2023-0717
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_delete_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2023-0724
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_add_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2023-0720
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_folder_order function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2023-0727
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_delete_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
+ 14 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2023-0722
|
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.18.17 |
Falsificación de petición en sitios cruzados (CSRF) |
Media
4,3
|
< 2.18.17
|
2.18.17 |
2023-02-07 |
✓ corregido en la última versión
|
|
CVE-2023-0723
|
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.18.17 |
Falsificación de petición en sitios cruzados (CSRF) |
Media
4,3
|
< 2.18.17
|
2.18.17 |
2023-02-07 |
✓ corregido en la última versión
|
|
CVE-2023-0718
|
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.18.17 |
Falta de control de autorización |
Media
4,3
|
< 2.18.17
|
2.18.17 |
2023-02-07 |
✓ corregido en la última versión
|
|
CVE-2023-0713
|
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.18.17 |
Falta de control de autorización |
Media
4,3
|
< 2.18.17
|
2.18.17 |
2023-02-07 |
✓ corregido en la última versión
|
|
CVE-2023-0712
|
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.18.17 |
Falta de control de autorización |
Media
4,3
|
< 2.18.17
|
2.18.17 |
2023-02-07 |
✓ corregido en la última versión
|
|
CVE-2023-0730
|
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.18.17 |
Falsificación de petición en sitios cruzados (CSRF) |
Media
4,3
|
< 2.18.17
|
2.18.17 |
2023-02-07 |
✓ corregido en la última versión
|
|
CVE-2023-0716
|
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.18.17 |
Falta de control de autorización |
Media
4,3
|
< 2.18.17
|
2.18.17 |
2023-02-07 |
✓ corregido en la última versión
|
|
CVE-2023-0725
|
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.18.17 |
Falsificación de petición en sitios cruzados (CSRF) |
Media
4,3
|
< 2.18.17
|
2.18.17 |
2023-02-07 |
✓ corregido en la última versión
|
|
CVE-2023-0726
|
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.18.17 |
Falsificación de petición en sitios cruzados (CSRF) |
Media
4,3
|
< 2.18.17
|
2.18.17 |
2023-02-07 |
✓ corregido en la última versión
|
|
CVE-2023-0729
|
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.18.17 |
Falsificación de petición en sitios cruzados (CSRF) |
Media
4,3
|
< 2.18.17
|
2.18.17 |
2023-02-07 |
✓ corregido en la última versión
|
|
CVE-2023-0684
|
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.18.17 |
Falta de control de autorización |
Media
4,3
|
< 2.18.17
|
2.18.17 |
2023-02-06 |
✓ corregido en la última versión
|
|
CVE-2023-0685
|
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.18.17 |
Falsificación de petición en sitios cruzados (CSRF) |
Media
4,3
|
< 2.18.17
|
2.18.17 |
2023-02-06 |
✓ corregido en la última versión
|
|
CVE-2021-24919
|
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.8.10 |
Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) |
Alta
8,8
|
< 2.8.10
|
2.8.10 |
2021-12-30 |
✓ corregido en la última versión
|
|
CVE-2026-1883
|
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 4.1.1 |
— |
Desconocido
|
< 4.1.1
|
4.1.1 |
0000-00-00 |
✓ corregido en la última versión
|
CVE-2023-0722
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_state function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2023-0723
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_move_object function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2023-0718
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2023-0713
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_add_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2023-0712
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_move_object function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2023-0730
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_folder_order function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2023-0716
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_edit_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2023-0725
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_clone_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2023-0726
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_edit_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2023-0729
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_sort_order function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2023-0684
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_unassign_folders function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as changing the folder structure maintained by the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2023-0685
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_unassign_folders function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin..
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2021-24919
The Wicked Folders WordPress plugin before 2.18.10 does not sanitise and escape the folder_id parameter before using it in a SQL statement in the wicked_folders_save_sort_order AJAX action, available to any authenticated user. leading to an SQL injection
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2026-1883
The Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via the delete_folders() function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary folders created by other users.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Mantén Wicked Folders actualizado — 4.1.3 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.