Cross-Site Request Forgery Vulnerability in Wicked Folders Plugin for WordPress
CVE-2023-0725
4.3MEDIUM
What is CVE-2023-0725?
The Wicked Folders plugin for WordPress has a vulnerability that allows unauthenticated attackers to exploit missing nonce validation in the ajax_clone_folder function. This issue enables attackers to trick site administrators into performing unauthorized actions, such as altering the plugin's folder structure, through crafted requests.
Affected Version(s)
Wicked Folders * <= 2.18.16