Cross-Site Request Forgery Vulnerability in Wicked Folders Plugin for WordPress
CVE-2023-0727
What is CVE-2023-0727?
The Wicked Folders plugin for WordPress is compromised by a Cross-Site Request Forgery vulnerability present in versions up to and including 2.18.16. This security flaw arises from inadequate nonce validation within the ajax_delete_folder function. As a result, unauthenticated attackers could exploit this vulnerability by tricking website administrators into initiating actions through manipulated requests. Such actions may lead to unauthorized alterations in the folder structure that the plugin manages, posing a significant risk to the integrity of website configurations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Wicked Folders * <= 2.18.16
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved