PLUGIN SECURITY

Is Wicked Folders safe?

Organize your pages, posts, and custom post types into folders. Upgrade to pro for media library folders, WooCommerce integration, and more.

What this plugin does

  • Slug: wicked-folders
  • Author: wickedplugins
  • 20000+ active installs
  • 98/100 rating (56 reviews on wordpress.org)
  • 726533 all-time downloads
  • On WordPress.org since 2017-04-06

foldersmedia library categoriesmedia library foldersorganizationpage folders

Maintenance status

  • Latest known version: 4.1.3
  • Last updated: 2026-06-23 6:38pm GMT
  • Tested up to WordPress: 7.0.4
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

22 known CVEs on file for Wicked Folders.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-0728, CVE-2023-0727, CVE-2023-0730, CVE-2023-0723, CVE-2023-0685, CVE-2023-0722, CVE-2023-0724, CVE-2023-0725, CVE-2023-0726, CVE-2023-0729 Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.18.17 Cross-Site Request Forgery (CSRF) Medium 4.3 < 2.18.17 2.18.17 2023-02-07 ✓ fixed in latest
CVE-2023-0715 Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.18.17 Missing Authorization Medium 4.3 < 2.18.17 2.18.17 2023-02-07 ✓ fixed in latest
CVE-2023-0711 Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.18.17 Missing Authorization Medium 4.3 < 2.18.17 2.18.17 2023-02-07 ✓ fixed in latest
CVE-2023-0719 Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.18.17 Missing Authorization Medium 4.3 < 2.18.17 2.18.17 2023-02-07 ✓ fixed in latest
CVE-2023-0717 Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.18.17 Missing Authorization Medium 4.3 < 2.18.17 2.18.17 2023-02-07 ✓ fixed in latest
CVE-2023-0724 Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.18.17 Cross-Site Request Forgery (CSRF) Medium 4.3 < 2.18.17 2.18.17 2023-02-07 ✓ fixed in latest
CVE-2023-0720 Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.18.17 Missing Authorization Medium 4.3 < 2.18.17 2.18.17 2023-02-07 ✓ fixed in latest
CVE-2023-0727 Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.18.17 Cross-Site Request Forgery (CSRF) Medium 4.3 < 2.18.17 2.18.17 2023-02-07 ✓ fixed in latest
+ 15 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-0722 Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.18.17 Cross-Site Request Forgery (CSRF) Medium 4.3 < 2.18.17 2.18.17 2023-02-07 ✓ fixed in latest
CVE-2023-0723 Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.18.17 Cross-Site Request Forgery (CSRF) Medium 4.3 < 2.18.17 2.18.17 2023-02-07 ✓ fixed in latest
CVE-2023-0718 Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.18.17 Missing Authorization Medium 4.3 < 2.18.17 2.18.17 2023-02-07 ✓ fixed in latest
CVE-2023-0713, CVE-2023-0712, CVE-2023-0718, CVE-2023-0719, CVE-2023-0684, CVE-2023-0711, CVE-2023-0715, CVE-2023-0716, CVE-2023-0717, CVE-2023-0720 Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.18.17 Missing Authorization Medium 4.3 < 2.18.17 2.18.17 2023-02-07 ✓ fixed in latest
CVE-2023-0712 Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.18.17 Missing Authorization Medium 4.3 < 2.18.17 2.18.17 2023-02-07 ✓ fixed in latest
CVE-2023-0730 Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.18.17 Cross-Site Request Forgery (CSRF) Medium 4.3 < 2.18.17 2.18.17 2023-02-07 ✓ fixed in latest
CVE-2023-0716 Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.18.17 Missing Authorization Medium 4.3 < 2.18.17 2.18.17 2023-02-07 ✓ fixed in latest
CVE-2023-0725 Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.18.17 Cross-Site Request Forgery (CSRF) Medium 4.3 < 2.18.17 2.18.17 2023-02-07 ✓ fixed in latest
CVE-2023-0726 Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.18.17 Cross-Site Request Forgery (CSRF) Medium 4.3 < 2.18.17 2.18.17 2023-02-07 ✓ fixed in latest
CVE-2023-0729 Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.18.17 Cross-Site Request Forgery (CSRF) Medium 4.3 < 2.18.17 2.18.17 2023-02-07 ✓ fixed in latest
CVE-2023-0684 Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.18.17 Missing Authorization Medium 4.3 < 2.18.17 2.18.17 2023-02-06 ✓ fixed in latest
CVE-2023-0685 Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.18.17 Cross-Site Request Forgery (CSRF) Medium 4.3 < 2.18.17 2.18.17 2023-02-06 ✓ fixed in latest
CVE-2021-24919 Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 2.8.10 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 8.8 < 2.8.10 2.8.10 2021-12-30 ✓ fixed in latest
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types [wicked-folders] < 4.1.1 Unknown < 4.1.1 4.1.1 0000-00-00 ✓ fixed in latest
CVE-2026-1883 Wicked Folders < 4.1.1 - Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Folder Deletion Unknown < 4.1.1 4.1.1 ✓ fixed in latest

How to fix it

Keep Wicked Folders updated — 4.1.3 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.