Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types — Vulnerabilities & Security Advisories 21

All 21 CVE vulnerabilities found in Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types, with AI-generated Chinese analysis, references, and POCs.

This page documents known security weaknesses affecting Wicked Folders, a folder organizer plugin for Pages, Posts, and Custom Post Types, specifically focusing on common vulnerability classes such as cross-site scripting and unauthorized access. It aggregates public security advisories, developer disclosures, and third-party reports to provide a comprehensive historical record of flaws identified in this WordPress extension. The data spans from the plugin’s initial release through recent updates, capturing incidents that range from low-severity configuration issues to high-risk exploits that could compromise site integrity. Here, you can track the vendor’s response timeline to various security incidents, understand the persistence and remediation efforts for specific weakness classes within the codebase, and look up the product’s vulnerability history to assess long-term maintenance quality. This resource is intended for security researchers, website administrators, and plugin auditors who need to evaluate the risk profile of Wicked Folders before deployment or during incident response. By centralizing these disparate reports, the page offers clarity on how the software handles user input, authentication mechanisms, and data validation over time. Users can identify patterns in flaw types, see which versions were affected, and gauge the effectiveness of subsequent patches. This structured overview supports informed decision-making regarding plugin usage and highlights areas where additional security hardening may be necessary. The information is derived from official changelogs, security bulletins, and community-contributed findings, ensuring a balanced and factual perspective without speculation.

Vendor: wickedplugins

CVE IDTitleCVSSSeverityPublished
CVE-2026-1883 Wicked Folders <= 4.1.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Folder Deletion CWE-639 4.3 Medium2026-03-15
CVE-2023-0729 Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_save_sort_order CWE-352 5.4 Medium2023-06-09
CVE-2023-0726 Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_edit_folder CWE-352 5.4 Medium2023-02-08
CVE-2023-0722 Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_save_state CWE-352 5.4 Medium2023-02-08
CVE-2023-0684 Wicked Folders <= 2.18.16 - Missing Authorization via ajax_unassign_folders CWE-862 5.4 Medium2023-02-08
CVE-2023-0715 Wicked Folders <= 2.18.16 - Missing Authorization on ajax_clone_folder CWE-862 5.4 Medium2023-02-08
CVE-2023-0711 Wicked Folders <= 2.18.16 - Missing Authorization via ajax_save_state CWE-862 5.4 Medium2023-02-08
CVE-2023-0717 Wicked Folders <= 2.18.16 - Missing Authorization via ajax_delete_folder CWE-862 5.4 Medium2023-02-08
CVE-2023-0725 Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_clone_folder CWE-352 5.4 Medium2023-02-08
CVE-2023-0724 Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_add_folder CWE-352 5.4 Medium2023-02-08
CVE-2023-0685 Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_unassign_folders CWE-352 5.4 Medium2023-02-08
CVE-2023-0720 Wicked Folders <= 2.18.16 - Missing Authorization on ajax_save_folder_order CWE-862 5.4 Medium2023-02-08
CVE-2023-0716 Wicked Folders <= 2.18.16 - Missing Authorization on ajax_edit_folder CWE-862 5.4 Medium2023-02-08
CVE-2023-0718 Wicked Folders <= 2.18.16 - Missing Authorization on ajax_save_folder CWE-862 5.4 Medium2023-02-07
CVE-2023-0723 Wicked Folders <= 2.18.16 - Cross-Site Request Forgery on ajax_move_object CWE-352 5.4 Medium2023-02-07
CVE-2023-0712 Wicked Folders <= 2.18.16 - Missing Authorization on ajax_move_object CWE-862 5.4 Medium2023-02-07
CVE-2023-0719 Wicked Folders <= 2.18.16 - Missing Authorization on ajax_save_sort_order CWE-862 5.4 Medium2023-02-07
CVE-2023-0730 Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_save_folder_order CWE-352 5.4 Medium2023-02-07
CVE-2023-0727 Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_delete_folder CWE-352 5.4 Medium2023-02-07
CVE-2023-0713 Wicked Folders <= 2.18.16 - Missing Authorization on ajax_add_folder CWE-862 5.4 Medium2023-02-07
CVE-2023-0728 Wicked Folders <= 2.18.16 - Cross-Site Request Forgery on ajax_save_folder CWE-352 5.4 Medium2023-02-07

All 21 known CVE vulnerabilities affecting Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types with full Chinese analysis, references, and POCs where available.