CVE · Medium

CVE-2023-0730 — Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.18.17

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-0730 Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.18.17 Cross-Site Request Forgery (CSRF) Medium 4.3 < 2.18.17 2.18.17 2023-02-07

CVE-2023-0730

The Wicked Folders plugin through version 2.18.16 contains a Cross-Site Request Forgery vulnerability in the ajax_save_folder_order function that lacks proper nonce verification. An attacker can exploit this flaw by crafting a malicious request that, if clicked by an administrator, allows unauthorized modification of the plugin's folder organization structure. The vulnerability requires social engineering to trick an admin into clicking a link but can result in changes to the site's folder hierarchy without legitimate authorization.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.