VYPR

Wicked Folders

by Wickedplugins

CVEs (21)

  • CVE-2023-0713MedFeb 7, 2023
    risk 0.35cvss 5.4epss 0.01

    The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_add_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and…

Page 2 of 2