
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1883 is an Insecure Direct Object Reference (IDOR) vulnerability in the Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types plugin for WordPress. It affects all versions up to and including 4.1.0, and allows authenticated attackers with Contributor-level access or above to delete arbitrary folders created by other users. The vulnerability was published on March 15–16, 2026, and assigned by Wordfence. It carries a CVSS v3.1 base score of 4.3 (Medium) (Wordfence, ENISA EUVD).
The root cause is classified as CWE-639: Authorization Bypass Through User-Controlled Key. Specifically, the delete_folders() function in the plugin fails to validate whether the folder being deleted belongs to the requesting user, allowing any authenticated user to supply an arbitrary folder ID (a user-controlled key) and delete folders owned by other users. No special configuration is required beyond having a Contributor-level (or higher) WordPress account, and the attack is conducted entirely over the network with low complexity and no user interaction required (Wordfence, WordPress Changeset).
Successful exploitation allows an authenticated attacker to delete folder structures created by other WordPress users, resulting in a limited integrity impact on site organization and content management workflows. There is no confidentiality impact (no data is exposed) and no direct availability impact on the underlying WordPress installation. The scope is limited to the plugin's folder management functionality, and lateral movement or privilege escalation is not directly enabled by this vulnerability (Wordfence, ENISA EUVD).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.026% (0.000260), indicating a very low probability of exploitation in the near term. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a valid WordPress account with at least Contributor-level privileges, which limits the attacker pool (Wordfence).
/wp-content/plugins/wicked-folders/readme.txt./wp-admin/admin-ajax.php) invoking the delete_folders() function with an arbitrary folder ID belonging to another user, bypassing ownership validation./wp-admin/admin-ajax.php with the action parameter referencing the Wicked Folders delete function, particularly from accounts with Contributor-level roles.Users should update the Wicked Folders plugin to version 4.1.1 or later, which includes the fix applied in the changeset that adds proper ownership validation to the delete_folders() function. The patch is available via the WordPress plugin repository. As a temporary workaround, site administrators can restrict Contributor-level user accounts or disable the Wicked Folders plugin until the update is applied (WordPress Changeset, Wordfence).
The vulnerability was reported and assigned by Wordfence, which published the advisory through its threat intelligence platform. Coverage has been limited to automated vulnerability aggregators and security databases, with no notable researcher commentary or significant social media discussion identified beyond standard CVE tracking (Wordfence, ENISA EUVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."