CVE · Medium

CVE-2023-0711 — Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.18.17

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-0711 Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.18.17 Missing Authorization Medium 4.3 < 2.18.17 2.18.17 2023-02-07

CVE-2023-0711

The Wicked Folders plugin for WordPress through version 2.18.16 contains an authorization bypass vulnerability in the ajax_save_state function that lacks proper capability verification. Authenticated users with subscriber-level access or higher can exploit this flaw to execute administrative functions, including altering how the plugin's folder structure is displayed. The vulnerability was patched in version 2.18.17.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.