Wicked Folders
cpe:2.3:a:wickedplugins:wicked_folders:*:*:*:*:wordpress:*:*
- <= 4.1.0
A vulnerability exists in the Wicked Folders WordPress plugin, specifically in versions up to and including 4.1.0. The issue arises from an Insecure Direct Object Reference (IDOR) in the delete_folders() function, where user-controlled keys are not properly validated. This flaw enables authenticated attackers with Contributor-level access or higher to delete folders created by other users.
Exploitation of this vulnerability allows for unauthorized deletion of folders, potentially leading to data loss for users whose folders are deleted.
Users are advised to update the Wicked Folders WordPress plugin to version 4.1.1 or a later patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.