Wicked Folders WordPress Plugin Insecure Direct Object Reference Vulnerability Allowing Arbitrary Folder Deletion

Vulnerability

A vulnerability exists in the Wicked Folders WordPress plugin, specifically in versions up to and including 4.1.0. The issue arises from an Insecure Direct Object Reference (IDOR) in the delete_folders() function, where user-controlled keys are not properly validated. This flaw enables authenticated attackers with Contributor-level access or higher to delete folders created by other users.

Impact

Exploitation of this vulnerability allows for unauthorized deletion of folders, potentially leading to data loss for users whose folders are deleted.

Remediation

Users are advised to update the Wicked Folders WordPress plugin to version 4.1.1 or a later patched version.

Added: Mar 16, 2026, 2:31 PM
Updated: Mar 16, 2026, 2:31 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
0.6
exploitability
6.1
remediation
7.7
relevance
4.0
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.