Wickedplugins develops WordPress plugin solutions with a focused product portfolio centered on Wicked Folders, a widely embedded file-management and organization component used across numerous WordPress installations. The vendor's vulnerability disclosures cluster around web-application input-handling and authorization weaknesses, including cross-site request forgery, missing authorization controls, and SQL injection, which are characteristic of plugin-layer exposure in the WordPress ecosystem. These weakness classes reflect the intersection of user-input acceptance and privilege-boundary enforcement that WordPress plugins must navigate. Defenders should monitor this vendor's releases closely given the broad plugin distribution and the authorization-oriented flaws that recur across its disclosures; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wickedplugins over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24919HIGH The Wicked Folders WordPress plugin before 2.8.10 does not sanitise and escape the folder_id parameter before using it in a SQL statement in the wicked_folders_save_sort_order AJAX | Feb 1, 2022 | 8.8 | 27 | NO | NO |
CVE-2023-0685MEDIUM The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation | Feb 8, 2023 | 4.3 | 18 | NO | NO |
CVE-2023-0719MEDIUM The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_sort_order function in versions up to, and includin | Feb 7, 2023 | 4.3 | 18 | NO | NO |
CVE-2023-0726MEDIUM The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation | Feb 8, 2023 | 4.3 | 17 | NO | NO |
CVE-2023-0724MEDIUM The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation | Feb 8, 2023 | 4.3 | 17 | NO | NO |
CVE-2023-0722MEDIUM The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation | Feb 8, 2023 | 4.3 | 17 | NO | NO |
CVE-2023-0716MEDIUM The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_edit_folder function in versions up to, and including, 2 | Feb 8, 2023 | 4.3 | 17 | NO | NO |
CVE-2023-0711MEDIUM The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_state function in versions up to, and including, 2. | Feb 8, 2023 | 4.3 | 17 | NO | NO |
CVE-2023-0730MEDIUM The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation | Feb 7, 2023 | 4.3 | 17 | NO | NO |
CVE-2023-0727MEDIUM The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation | Feb 7, 2023 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wickedplugins.
Media articles that mention a CVE ID that affects a product developed by Wickedplugins — matched by CVE ID, not by vendor name.