Authorization Bypass in Wicked Folders Plugin for WordPress
CVE-2023-0711
4.3MEDIUM
What is CVE-2023-0711?
The Wicked Folders plugin for WordPress contains a significant security flaw that allows authenticated users, including those with only subscriber-level permissions, to bypass authorization mechanisms. This vulnerability arises from the absence of a capability check in the ajax_save_state function, which can be exploited to perform administrative actions such as altering the folder structure within the plugin. This compromise can lead to unauthorized access and manipulation of folder visibility settings, posing a serious risk to the integrity of website management for users relying on this plugin.
Affected Version(s)
Wicked Folders * <= 2.18.16