Cross-Site Request Forgery Vulnerability in Wicked Folders Plugin for WordPress
CVE-2023-0724
4.3MEDIUM
What is CVE-2023-0724?
The Wicked Folders plugin for WordPress has a vulnerability due to improper nonce validation in the ajax_add_folder function, affecting versions up to 2.18.16. This allows unauthenticated attackers to send malicious requests, potentially causing significant changes to the folder structure managed by the plugin. Attackers can exploit this vulnerability by tricking administrators into clicking on deceitful links, leading to unauthorized actions that compromise site integrity.
Affected Version(s)
Wicked Folders * <= 2.18.16