| CVE-2026-1883 | Wicked Folders <= 4.1.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Folder Deletion | wickedplugins | Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types | Medium | 4.3 | 2026-03-15 01:19:06 | Deep Dive |
| CVE-2023-0729 | Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_save_sort_order | wickedplugins | Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types | Medium | 5.4 | 2023-06-09 05:33:28 | Deep Dive |
| CVE-2023-0726 | Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_edit_folder | wickedplugins | Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types | Medium | 5.4 | 2023-02-08 01:13:17 | Deep Dive |
| CVE-2023-0722 | Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_save_state | wickedplugins | Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types | Medium | 5.4 | 2023-02-08 01:12:54 | Deep Dive |
| CVE-2023-0684 | Wicked Folders <= 2.18.16 - Missing Authorization via ajax_unassign_folders | wickedplugins | Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types | Medium | 5.4 | 2023-02-08 01:12:10 | Deep Dive |
| CVE-2023-0715 | Wicked Folders <= 2.18.16 - Missing Authorization on ajax_clone_folder | wickedplugins | Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types | Medium | 5.4 | 2023-02-08 01:11:22 | Deep Dive |
| CVE-2023-0711 | Wicked Folders <= 2.18.16 - Missing Authorization via ajax_save_state | wickedplugins | Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types | Medium | 5.4 | 2023-02-08 01:10:18 | Deep Dive |
| CVE-2023-0717 | Wicked Folders <= 2.18.16 - Missing Authorization via ajax_delete_folder | wickedplugins | Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types | Medium | 5.4 | 2023-02-08 01:09:32 | Deep Dive |
| CVE-2023-0725 | Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_clone_folder | wickedplugins | Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types | Medium | 5.4 | 2023-02-08 01:08:04 | Deep Dive |
| CVE-2023-0724 | Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_add_folder | wickedplugins | Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types | Medium | 5.4 | 2023-02-08 01:04:51 | Deep Dive |
| CVE-2023-0685 | Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_unassign_folders | wickedplugins | Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types | Medium | 5.4 | 2023-02-08 01:03:51 | Deep Dive |
| CVE-2023-0720 | Wicked Folders <= 2.18.16 - Missing Authorization on ajax_save_folder_order | wickedplugins | Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types | Medium | 5.4 | 2023-02-08 01:03:26 | Deep Dive |
| CVE-2023-0716 | Wicked Folders <= 2.18.16 - Missing Authorization on ajax_edit_folder | wickedplugins | Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types | Medium | 5.4 | 2023-02-08 01:02:53 | Deep Dive |
| CVE-2023-0718 | Wicked Folders <= 2.18.16 - Missing Authorization on ajax_save_folder | wickedplugins | Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types | Medium | 5.4 | 2023-02-07 23:07:25 | Deep Dive |
| CVE-2023-0723 | Wicked Folders <= 2.18.16 - Cross-Site Request Forgery on ajax_move_object | wickedplugins | Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types | Medium | 5.4 | 2023-02-07 22:57:37 | Deep Dive |
| CVE-2023-0712 | Wicked Folders <= 2.18.16 - Missing Authorization on ajax_move_object | wickedplugins | Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types | Medium | 5.4 | 2023-02-07 22:57:08 | Deep Dive |
| CVE-2023-0719 | Wicked Folders <= 2.18.16 - Missing Authorization on ajax_save_sort_order | wickedplugins | Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types | Medium | 5.4 | 2023-02-07 22:56:45 | Deep Dive |
| CVE-2023-0730 | Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_save_folder_order | wickedplugins | Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types | Medium | 5.4 | 2023-02-07 22:50:05 | Deep Dive |
| CVE-2023-0727 | Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_delete_folder | wickedplugins | Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types | Medium | 5.4 | 2023-02-07 22:49:27 | Deep Dive |
| CVE-2023-0713 | Wicked Folders <= 2.18.16 - Missing Authorization on ajax_add_folder | wickedplugins | Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types | Medium | 5.4 | 2023-02-07 21:05:36 | Deep Dive |