Cross-Site Request Forgery Vulnerability in Wicked Folders Plugin for WordPress
CVE-2023-0724
4.3MEDIUM
Summary
The Wicked Folders plugin for WordPress has a vulnerability due to improper nonce validation in the ajax_add_folder function, affecting versions up to 2.18.16. This allows unauthenticated attackers to send malicious requests, potentially causing significant changes to the folder structure managed by the plugin. Attackers can exploit this vulnerability by tricking administrators into clicking on deceitful links, leading to unauthorized actions that compromise site integrity.
Affected Version(s)
Wicked Folders * <= 2.18.16
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Marco Wotschka