← WordPress Vulnerabilities
WordPress security by component

Wicked Folders

Wicked Folders is a WordPress component with 21 published CVE records in this archive. The latest tracked vulnerability was published Jun 09, 2023; the highest CVE/CNA score is 8.8.

Plugin slug: wicked-folders

CVE-2023-0729: Wicked Folders: Cross-site request forgery

Wicked Folders is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.

PublishedJun 09, 2023
Safe version guidanceSee mitigation notes
Safe version
Jun 09, 2023 CVE-2023-0729
Wicked Folders: Cross-site request forgery
Wicked Folders is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD4.3
Feb 08, 2023 CVE-2023-0726
Wicked Folders: Cross-site request forgery
Wicked Folders is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD4.3
Feb 08, 2023 CVE-2023-0725
Wicked Folders: Cross-site request forgery
Wicked Folders is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD4.3
Feb 08, 2023 CVE-2023-0724
Wicked Folders: Cross-site request forgery
Wicked Folders is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD4.3
Feb 08, 2023 CVE-2023-0722
Wicked Folders: Cross-site request forgery
Wicked Folders is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD4.3
Feb 08, 2023 CVE-2023-0720
Wicked Folders: A security weakness
Wicked Folders is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD4.3
Feb 08, 2023 CVE-2023-0717
Wicked Folders: A security weakness
Wicked Folders is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD4.3
Feb 08, 2023 CVE-2023-0716
Wicked Folders: A security weakness
Wicked Folders is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD4.3
Feb 08, 2023 CVE-2023-0715
Wicked Folders: A security weakness
Wicked Folders is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD4.3
Feb 08, 2023 CVE-2023-0711
Wicked Folders: A security weakness
Wicked Folders is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD4.3
Feb 08, 2023 CVE-2023-0685
Wicked Folders: Cross-site request forgery
Wicked Folders is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD4.3
Feb 08, 2023 CVE-2023-0684
Wicked Folders: A security weakness
Wicked Folders is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD4.3
Feb 08, 2023 CVE-2023-0718
Wicked Folders: A security weakness
Wicked Folders is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD4.3
Feb 07, 2023 CVE-2023-0730
Wicked Folders: Cross-site request forgery
Wicked Folders is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD4.3
Feb 07, 2023 CVE-2023-0727
Wicked Folders: Cross-site request forgery
Wicked Folders is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD4.3
Feb 07, 2023 CVE-2023-0723
Wicked Folders: Cross-site request forgery
Wicked Folders is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD4.3
Feb 07, 2023 CVE-2023-0719
Wicked Folders: A security weakness
Wicked Folders is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD4.3
Feb 07, 2023 CVE-2023-0712
Wicked Folders: A security weakness
Wicked Folders is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD4.3
Feb 07, 2023 CVE-2023-0728
Wicked Folders: Cross-site request forgery
Wicked Folders is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD4.3
Feb 07, 2023 CVE-2023-0713
Wicked Folders: A security weakness
Wicked Folders is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD4.3
Feb 01, 2022 CVE-2021-24919
Wicked Folders: SQL injection
Wicked Folders is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVD8.8