CVE-2026-1883
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-1883 is an Insecure Direct Object Reference (IDOR) vulnerability in the Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types plugin for WordPress. It affects all versions up to and including 4.1.0, and allows authenticated attackers with Contributor-level access or above to delete arbitrary folders created by other users. The vulnerability was published on March 15–16, 2026, and assigned by Wordfence. It carries a CVSS v3.1 base score of 4.3 (Medium) (Wordfence, ENISA EUVD).

Technical details

The root cause is classified as CWE-639: Authorization Bypass Through User-Controlled Key. Specifically, the delete_folders() function in the plugin fails to validate whether the folder being deleted belongs to the requesting user, allowing any authenticated user to supply an arbitrary folder ID (a user-controlled key) and delete folders owned by other users. No special configuration is required beyond having a Contributor-level (or higher) WordPress account, and the attack is conducted entirely over the network with low complexity and no user interaction required (Wordfence, WordPress Changeset).

Impact

Successful exploitation allows an authenticated attacker to delete folder structures created by other WordPress users, resulting in a limited integrity impact on site organization and content management workflows. There is no confidentiality impact (no data is exposed) and no direct availability impact on the underlying WordPress installation. The scope is limited to the plugin's folder management functionality, and lateral movement or privilege escalation is not directly enabled by this vulnerability (Wordfence, ENISA EUVD).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.026% (0.000260), indicating a very low probability of exploitation in the near term. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a valid WordPress account with at least Contributor-level privileges, which limits the attacker pool (Wordfence).

Exploitation steps

  1. Reconnaissance: Identify a WordPress site running the Wicked Folders plugin version ≤ 4.1.0. This can be done by checking the plugin's readme or version file at /wp-content/plugins/wicked-folders/readme.txt.
  2. Obtain authenticated access: Register or use an existing WordPress account with at least Contributor-level privileges on the target site.
  3. Enumerate folder IDs: Browse the WordPress admin panel or use authenticated API requests to identify folder IDs created by other users within the Wicked Folders plugin interface.
  4. Craft a malicious request: Send an authenticated POST request to the WordPress admin AJAX endpoint (/wp-admin/admin-ajax.php) invoking the delete_folders() function with an arbitrary folder ID belonging to another user, bypassing ownership validation.
  5. Delete target folders: The server processes the request without verifying folder ownership, resulting in deletion of the targeted folder (Wordfence, WordPress Changeset).

Indicators of compromise

  • Logs: WordPress access logs showing repeated authenticated POST requests to /wp-admin/admin-ajax.php with the action parameter referencing the Wicked Folders delete function, particularly from accounts with Contributor-level roles.
  • Application Logs: Unexpected deletion events for folders not owned by the requesting user recorded in WordPress debug logs or audit trail plugins.
  • Behavioral: Multiple folders disappearing from the WordPress admin panel without corresponding administrative action by their owners.

Mitigation and workarounds

Users should update the Wicked Folders plugin to version 4.1.1 or later, which includes the fix applied in the changeset that adds proper ownership validation to the delete_folders() function. The patch is available via the WordPress plugin repository. As a temporary workaround, site administrators can restrict Contributor-level user accounts or disable the Wicked Folders plugin until the update is applied (WordPress Changeset, Wordfence).

Community reactions

The vulnerability was reported and assigned by Wordfence, which published the advisory through its threat intelligence platform. Coverage has been limited to automated vulnerability aggregators and security databases, with no notable researcher commentary or significant social media discussion identified beyond standard CVE tracking (Wordfence, ENISA EUVD).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-83547MEDIUM6.8
  • xpro-elementor-addons
NoYesSep 02, 2026
CVE-2026-82884MEDIUM6.8
  • all-in-one-seo-pack
NoYesSep 02, 2026
CVE-2026-8151MEDIUM5.4
  • simple-membership-mailchimp-integration
NoYesSep 02, 2026
CVE-2026-83533MEDIUM5.3
  • wp-express-checkout
NoYesSep 02, 2026
CVE-2026-81571MEDIUM4.8
  • brave-popup-builder
NoYesSep 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management