Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesWicked Folders

Wicked Folders vulnerabilities

Wicked Folders has 22 known vulnerabilities in this database. The most recent published record is dated 16 Mar 2026.

Known vulnerabilities
22
Active installs
20,000+
Latest version
4.1.3
Last updated
1 Sep 2026
Most recent
16 Mar 2026

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Broken access control
CVE-2026-1883
Medium 4.3Up to 4.1.0Fixed in a later version (latest 4.1.3)16 Mar 2026
Cross-site request forgery (CSRF)
CVE-2023-0729
Medium 5.4Up to 2.18.16Fixed in a later version (latest 4.1.3)9 Jun 2023
Broken access control
CVE-2023-0716
Medium 5.4Up to 2.18.16Fixed in a later version (latest 4.1.3)8 Feb 2023
Broken access control
CVE-2023-0717
Medium 5.4Up to 2.18.16Fixed in a later version (latest 4.1.3)8 Feb 2023
Broken access control
CVE-2023-0720
Medium 5.4Up to 2.18.16Fixed in a later version (latest 4.1.3)8 Feb 2023
Cross-site request forgery (CSRF)
CVE-2023-0722
Medium 5.4Up to 2.18.16Fixed in a later version (latest 4.1.3)8 Feb 2023
Cross-site request forgery (CSRF)
CVE-2023-0724
Medium 5.4Up to 2.18.16Fixed in a later version (latest 4.1.3)8 Feb 2023
Cross-site request forgery (CSRF)
CVE-2023-0725
Medium 5.4Up to 2.18.16Fixed in a later version (latest 4.1.3)8 Feb 2023
Cross-site request forgery (CSRF)
CVE-2023-0726
Medium 5.4Up to 2.18.16Fixed in a later version (latest 4.1.3)8 Feb 2023
Broken access control
CVE-2023-0684
Medium 5.4Up to 2.18.16Fixed in a later version (latest 4.1.3)8 Feb 2023
Cross-site request forgery (CSRF)
CVE-2023-0685
Medium 5.4Up to 2.18.16Fixed in a later version (latest 4.1.3)8 Feb 2023
Broken access control
CVE-2023-0711
Medium 5.4Up to 2.18.16Fixed in a later version (latest 4.1.3)8 Feb 2023
Broken access control
CVE-2023-0715
Medium 5.4Up to 2.18.16Fixed in a later version (latest 4.1.3)8 Feb 2023
Broken access control
CVE-2023-0718
Medium 5.4Up to 2.18.16Fixed in a later version (latest 4.1.3)8 Feb 2023
Cross-site request forgery (CSRF)
CVE-2023-0723
Medium 5.4Up to 2.18.16Fixed in a later version (latest 4.1.3)7 Feb 2023
Cross-site request forgery (CSRF)
CVE-2023-0727
Medium 5.4Up to 2.18.16Fixed in a later version (latest 4.1.3)7 Feb 2023
Cross-site request forgery (CSRF)
CVE-2023-0730
Medium 5.4Up to 2.18.16Fixed in a later version (latest 4.1.3)7 Feb 2023
Broken access control
CVE-2023-0712
Medium 5.4Up to 2.18.16Fixed in a later version (latest 4.1.3)7 Feb 2023
Broken access control
CVE-2023-0719
Medium 5.4Up to 2.18.16Fixed in a later version (latest 4.1.3)7 Feb 2023
Broken access control
CVE-2023-0713
Medium 5.4Up to 2.18.16Fixed in a later version (latest 4.1.3)7 Feb 2023
Cross-site request forgery (CSRF)
CVE-2023-0728
Medium 5.4Up to 2.18.16Fixed in a later version (latest 4.1.3)7 Feb 2023
SQL injection
CVE-2021-24919
High 8.8Before 2.18.10Fixed in 2.18.101 Feb 2022
Read the published descriptions
CVE-2026-1883, 16 Mar 2026
The Wicked Folders - Folder Organizer for Pages, Posts, and Custom Post Types plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via the delete_folders() function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary folders created by other users. CVE record
CVE-2023-0729, 9 Jun 2023
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_sort_order function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin. CVE record
CVE-2023-0716, 8 Feb 2023
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_edit_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin. CVE record
CVE-2023-0717, 8 Feb 2023
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_delete_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin. CVE record
CVE-2023-0720, 8 Feb 2023
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_folder_order function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin. CVE record
CVE-2023-0722, 8 Feb 2023
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_state function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin. CVE record
CVE-2023-0724, 8 Feb 2023
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_add_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin. CVE record
CVE-2023-0725, 8 Feb 2023
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_clone_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin. CVE record
CVE-2023-0726, 8 Feb 2023
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_edit_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin. CVE record
CVE-2023-0684, 8 Feb 2023
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_unassign_folders function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as changing the folder structure maintained by the plugin. CVE record
CVE-2023-0685, 8 Feb 2023
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_unassign_folders function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin.. CVE record
CVE-2023-0711, 8 Feb 2023
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_state function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the view state of the folder structure maintained by the plugin. CVE record
CVE-2023-0715, 8 Feb 2023
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_clone_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin. CVE record
CVE-2023-0718, 8 Feb 2023
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin. CVE record
CVE-2023-0723, 7 Feb 2023
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_move_object function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin. CVE record
CVE-2023-0727, 7 Feb 2023
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_delete_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin. CVE record
CVE-2023-0730, 7 Feb 2023
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_folder_order function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin. CVE record
CVE-2023-0712, 7 Feb 2023
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_move_object function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin. CVE record
CVE-2023-0719, 7 Feb 2023
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_sort_order function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin. CVE record
CVE-2023-0713, 7 Feb 2023
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_add_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin. CVE record
CVE-2023-0728, 7 Feb 2023
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin. CVE record
CVE-2021-24919, 1 Feb 2022
The Wicked Folders WordPress plugin before 2.8.10 does not sanitise and escape the folder_id parameter before using it in a SQL statement in the wicked_folders_save_sort_order AJAX action, available to any authenticated user. leading to an SQL injection CVE record

What to do if you run Wicked Folders

If you run Wicked Folders, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new Wicked Folders vulnerabilities

Free. We email you when a new vulnerability is published for Wicked Folders, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support