Cross-Site Request Forgery in Wicked Folders Plugin for WordPress
CVE-2023-0729
4.3MEDIUM
What is CVE-2023-0729?
The Wicked Folders plugin for WordPress contains a vulnerability that allows unauthenticated attackers to exploit a flaw in the ajax_save_sort_order function due to insufficient nonce validation. This security oversight can lead to unauthorized actions, enabling attackers to manipulate folder structures by tricking a site administrator into executing malicious requests. This vulnerability affects all versions of the plugin up to and including 2.18.16.
Affected Version(s)
Wicked Folders * <= 2.18.16