HomeWordPress vulnerabilitiesWicked Folders
Wicked Folders vulnerabilities
Wicked Folders has 22 known vulnerabilities in this database. The most recent published record is dated 16 Mar 2026.
- Known vulnerabilities
- 22
- Active installs
- 20,000+
- Latest version
- 4.1.3
- Last updated
- 1 Sep 2026
- Most recent
- 16 Mar 2026
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Broken access control CVE-2026-1883 | Medium 4.3 | Up to 4.1.0 | Fixed in a later version (latest 4.1.3) | 16 Mar 2026 |
| Cross-site request forgery (CSRF) CVE-2023-0729 | Medium 5.4 | Up to 2.18.16 | Fixed in a later version (latest 4.1.3) | 9 Jun 2023 |
| Broken access control CVE-2023-0716 | Medium 5.4 | Up to 2.18.16 | Fixed in a later version (latest 4.1.3) | 8 Feb 2023 |
| Broken access control CVE-2023-0717 | Medium 5.4 | Up to 2.18.16 | Fixed in a later version (latest 4.1.3) | 8 Feb 2023 |
| Broken access control CVE-2023-0720 | Medium 5.4 | Up to 2.18.16 | Fixed in a later version (latest 4.1.3) | 8 Feb 2023 |
| Cross-site request forgery (CSRF) CVE-2023-0722 | Medium 5.4 | Up to 2.18.16 | Fixed in a later version (latest 4.1.3) | 8 Feb 2023 |
| Cross-site request forgery (CSRF) CVE-2023-0724 | Medium 5.4 | Up to 2.18.16 | Fixed in a later version (latest 4.1.3) | 8 Feb 2023 |
| Cross-site request forgery (CSRF) CVE-2023-0725 | Medium 5.4 | Up to 2.18.16 | Fixed in a later version (latest 4.1.3) | 8 Feb 2023 |
| Cross-site request forgery (CSRF) CVE-2023-0726 | Medium 5.4 | Up to 2.18.16 | Fixed in a later version (latest 4.1.3) | 8 Feb 2023 |
| Broken access control CVE-2023-0684 | Medium 5.4 | Up to 2.18.16 | Fixed in a later version (latest 4.1.3) | 8 Feb 2023 |
| Cross-site request forgery (CSRF) CVE-2023-0685 | Medium 5.4 | Up to 2.18.16 | Fixed in a later version (latest 4.1.3) | 8 Feb 2023 |
| Broken access control CVE-2023-0711 | Medium 5.4 | Up to 2.18.16 | Fixed in a later version (latest 4.1.3) | 8 Feb 2023 |
| Broken access control CVE-2023-0715 | Medium 5.4 | Up to 2.18.16 | Fixed in a later version (latest 4.1.3) | 8 Feb 2023 |
| Broken access control CVE-2023-0718 | Medium 5.4 | Up to 2.18.16 | Fixed in a later version (latest 4.1.3) | 8 Feb 2023 |
| Cross-site request forgery (CSRF) CVE-2023-0723 | Medium 5.4 | Up to 2.18.16 | Fixed in a later version (latest 4.1.3) | 7 Feb 2023 |
| Cross-site request forgery (CSRF) CVE-2023-0727 | Medium 5.4 | Up to 2.18.16 | Fixed in a later version (latest 4.1.3) | 7 Feb 2023 |
| Cross-site request forgery (CSRF) CVE-2023-0730 | Medium 5.4 | Up to 2.18.16 | Fixed in a later version (latest 4.1.3) | 7 Feb 2023 |
| Broken access control CVE-2023-0712 | Medium 5.4 | Up to 2.18.16 | Fixed in a later version (latest 4.1.3) | 7 Feb 2023 |
| Broken access control CVE-2023-0719 | Medium 5.4 | Up to 2.18.16 | Fixed in a later version (latest 4.1.3) | 7 Feb 2023 |
| Broken access control CVE-2023-0713 | Medium 5.4 | Up to 2.18.16 | Fixed in a later version (latest 4.1.3) | 7 Feb 2023 |
| Cross-site request forgery (CSRF) CVE-2023-0728 | Medium 5.4 | Up to 2.18.16 | Fixed in a later version (latest 4.1.3) | 7 Feb 2023 |
| SQL injection CVE-2021-24919 | High 8.8 | Before 2.18.10 | Fixed in 2.18.10 | 1 Feb 2022 |
Read the published descriptions
- CVE-2026-1883, 16 Mar 2026
- The Wicked Folders - Folder Organizer for Pages, Posts, and Custom Post Types plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via the delete_folders() function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary folders created by other users. CVE record
- CVE-2023-0729, 9 Jun 2023
- The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_sort_order function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin. CVE record
- CVE-2023-0716, 8 Feb 2023
- The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_edit_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin. CVE record
- CVE-2023-0717, 8 Feb 2023
- The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_delete_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin. CVE record
- CVE-2023-0720, 8 Feb 2023
- The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_folder_order function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin. CVE record
- CVE-2023-0722, 8 Feb 2023
- The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_state function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin. CVE record
- CVE-2023-0724, 8 Feb 2023
- The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_add_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin. CVE record
- CVE-2023-0725, 8 Feb 2023
- The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_clone_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin. CVE record
- CVE-2023-0726, 8 Feb 2023
- The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_edit_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin. CVE record
- CVE-2023-0684, 8 Feb 2023
- The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_unassign_folders function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as changing the folder structure maintained by the plugin. CVE record
- CVE-2023-0685, 8 Feb 2023
- The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_unassign_folders function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin.. CVE record
- CVE-2023-0711, 8 Feb 2023
- The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_state function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the view state of the folder structure maintained by the plugin. CVE record
- CVE-2023-0715, 8 Feb 2023
- The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_clone_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin. CVE record
- CVE-2023-0718, 8 Feb 2023
- The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin. CVE record
- CVE-2023-0723, 7 Feb 2023
- The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_move_object function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin. CVE record
- CVE-2023-0727, 7 Feb 2023
- The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_delete_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin. CVE record
- CVE-2023-0730, 7 Feb 2023
- The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_folder_order function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin. CVE record
- CVE-2023-0712, 7 Feb 2023
- The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_move_object function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin. CVE record
- CVE-2023-0719, 7 Feb 2023
- The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_sort_order function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin. CVE record
- CVE-2023-0713, 7 Feb 2023
- The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_add_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform actions intended for administrators such as modifying the folder structure maintained by the plugin. CVE record
- CVE-2023-0728, 7 Feb 2023
- The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted they can trick a site administrator into performing an action such as clicking on a link leading them to perform actions intended for administrators such as changing the folder structure maintained by the plugin. CVE record
- CVE-2021-24919, 1 Feb 2022
- The Wicked Folders WordPress plugin before 2.8.10 does not sanitise and escape the folder_id parameter before using it in a SQL statement in the wicked_folders_save_sort_order AJAX action, available to any authenticated user. leading to an SQL injection CVE record
What to do if you run Wicked Folders
If you run Wicked Folders, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new Wicked Folders vulnerabilities
Free. We email you when a new vulnerability is published for Wicked Folders, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.