Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types

41 known CVEs 20K+ active installs

Scan My Site Free

UNKNOWN: 41
Known Vulnerabilities 41
CVE-2026-1883 UNKNOWN EPSS 0.1%
Published 2026-03-16 · Affected: *
The Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via the
CVE-2023-0729 UNKNOWN EPSS 0.2%
Published 2023-06-09 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_sor
CVE-2023-0729 UNKNOWN EPSS 0.2%
Published 2023-06-09 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_sor
CVE-2023-0726 UNKNOWN EPSS 0.2%
Published 2023-02-08 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_edit_fol
CVE-2023-0726 UNKNOWN EPSS 0.2%
Published 2023-02-08 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_edit_fol
CVE-2023-0725 UNKNOWN EPSS 0.2%
Published 2023-02-08 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_clone_fo
CVE-2023-0725 UNKNOWN EPSS 0.2%
Published 2023-02-08 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_clone_fo
CVE-2023-0724 UNKNOWN EPSS 0.2%
Published 2023-02-08 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_add_fold
CVE-2023-0724 UNKNOWN EPSS 0.2%
Published 2023-02-08 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_add_fold
CVE-2023-0722 UNKNOWN EPSS 0.2%
Published 2023-02-08 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_sta
CVE-2023-0722 UNKNOWN EPSS 0.2%
Published 2023-02-08 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_sta
CVE-2023-0720 UNKNOWN EPSS 0.5%
Published 2023-02-08 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_folder_order function in versions up to, and including, 2.18.16. This m
CVE-2023-0720 UNKNOWN EPSS 0.5%
Published 2023-02-08 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_folder_order function in versions up to, and including, 2.18.16. This m
CVE-2023-0717 UNKNOWN EPSS 0.5%
Published 2023-02-08 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_delete_folder function in versions up to, and including, 2.18.16. This makes
CVE-2023-0717 UNKNOWN EPSS 0.5%
Published 2023-02-08 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_delete_folder function in versions up to, and including, 2.18.16. This makes
CVE-2023-0716 UNKNOWN EPSS 0.5%
Published 2023-02-08 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_edit_folder function in versions up to, and including, 2.18.16. This makes i
CVE-2023-0716 UNKNOWN EPSS 0.5%
Published 2023-02-08 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_edit_folder function in versions up to, and including, 2.18.16. This makes i
CVE-2023-0715 UNKNOWN EPSS 0.5%
Published 2023-02-08 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_clone_folder function in versions up to, and including, 2.18.16. This makes
CVE-2023-0715 UNKNOWN EPSS 0.5%
Published 2023-02-08 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_clone_folder function in versions up to, and including, 2.18.16. This makes
CVE-2023-0711 UNKNOWN EPSS 0.5%
Published 2023-02-08 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_state function in versions up to, and including, 2.18.16. This makes it
CVE-2023-0711 UNKNOWN EPSS 0.5%
Published 2023-02-08 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_state function in versions up to, and including, 2.18.16. This makes it
CVE-2023-0685 UNKNOWN EPSS 0.2%
Published 2023-02-08 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_unassign
CVE-2023-0685 UNKNOWN EPSS 0.2%
Published 2023-02-08 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_unassign
CVE-2023-0684 UNKNOWN EPSS 0.5%
Published 2023-02-08 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_unassign_folders function in versions up to, and including, 2.18.16. This ma
CVE-2023-0684 UNKNOWN EPSS 0.5%
Published 2023-02-08 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_unassign_folders function in versions up to, and including, 2.18.16. This ma
CVE-2023-0718 UNKNOWN EPSS 0.5%
Published 2023-02-08 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_folder function in versions up to, and including, 2.18.16. This makes i
CVE-2023-0718 UNKNOWN EPSS 0.5%
Published 2023-02-08 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_folder function in versions up to, and including, 2.18.16. This makes i
CVE-2023-0730 UNKNOWN EPSS 0.2%
Published 2023-02-07 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_fol
CVE-2023-0730 UNKNOWN EPSS 0.2%
Published 2023-02-07 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_fol
CVE-2023-0727 UNKNOWN EPSS 0.2%
Published 2023-02-07 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_delete_f
CVE-2023-0727 UNKNOWN EPSS 0.2%
Published 2023-02-07 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_delete_f
CVE-2023-0723 UNKNOWN EPSS 0.2%
Published 2023-02-07 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_move_obj
CVE-2023-0723 UNKNOWN EPSS 0.2%
Published 2023-02-07 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_move_obj
CVE-2023-0719 UNKNOWN EPSS 0.5%
Published 2023-02-07 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_sort_order function in versions up to, and including, 2.18.16. This mak
CVE-2023-0719 UNKNOWN EPSS 0.5%
Published 2023-02-07 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_sort_order function in versions up to, and including, 2.18.16. This mak
CVE-2023-0712 UNKNOWN EPSS 0.5%
Published 2023-02-07 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_move_object function in versions up to, and including, 2.18.16. This makes i
CVE-2023-0712 UNKNOWN EPSS 0.5%
Published 2023-02-07 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_move_object function in versions up to, and including, 2.18.16. This makes i
CVE-2023-0728 UNKNOWN EPSS 0.2%
Published 2023-02-07 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_fol
CVE-2023-0728 UNKNOWN EPSS 0.2%
Published 2023-02-07 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_fol
CVE-2023-0713 UNKNOWN EPSS 0.5%
Published 2023-02-07 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_add_folder function in versions up to, and including, 2.18.16. This makes it
CVE-2023-0713 UNKNOWN EPSS 0.5%
Published 2023-02-07 · Affected: *
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_add_folder function in versions up to, and including, 2.18.16. This makes it

Is Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types running on your site?

A free scan detects your plugins and flags any that match these CVEs.

Scan My Site Free