Wicked Folders <= 4.1.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Folder Deletion
Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types
Minimum safe version
4.1.1
Update to 4.1.1 or later to address 22 fixable vulnerabilities
CVE-2023-0729
CVE-2023-0726
CVE-2023-0725
CVE-2023-0716
WordPress Wicked Folders Plugin <= 2.18.16 is vulnerable to Cross Site Request Forgery (CSRF)
WordPress Wicked Folders Plugin <= 2.18.16 is vulnerable to Broken Access Control
WordPress Wicked Folders Plugin <= 2.18.16 is vulnerable to Broken Access Control
WordPress Wicked Folders Plugin <= 2.18.16 is vulnerable to Broken Access Control
WordPress Wicked Folders Plugin <= 2.18.16 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2023-0722
WordPress Wicked Folders Plugin <= 2.18.16 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2023-0685
CVE-2023-0684
CVE-2023-0720
CVE-2023-0724
CVE-2023-0717
WordPress Wicked Folders Plugin <= 2.18.16 is vulnerable to Broken Access Control
CVE-2023-0711
CVE-2023-0715
WordPress Wicked Folders Plugin <= 2.18.16 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2021-24919