Intuitive Custom Post Order <= 3.1.4.1 - Authenticated (Admin+) SQL Injection
medium
The Intuitive Custom Post Order plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.1.4.1, due to insufficient escaping on the user supplied 'objects' and 'tags' parameters and lack of sufficient preparation in the 'update_options' function as well as the 'refresh' function which run...
- CVSS:
- 6.6
- Affected:
- up to 3.1.4
- Fixed in:
- 3.1.5
- Disclosed:
- Jan 25, 2023
CVE-2023-1016 on NVD →
Intuitive Custom Post Order <= 3.1.3 - Missing Authorization to Authenticated Settings Change
medium
The Intuitive Custom Post Order plugin for WordPress is vulnerable to authenticated settings change in versions up to and including 3.1.3 via the 'update-menu-order-sites' AJAX action. This allows authenticated attackers with subscriber privileges or above, to change the order of sites in the sites menu on multisite in...
- CVSS:
- 4.3
- Affected:
- up to 3.1.3
- Fixed in:
- 3.1.4
- Disclosed:
- Jan 25, 2023
Intuitive Custom Post Order <= 3.1.3 - Missing Authorization to Authenticated Settings Change
medium
The Intuitive Custom Post Order plugin for WordPress is vulnerable to authenticated settings change in versions up to and including 3.1.3 via the 'update-menu-order' AJAX action. This allows authenticated attackers with subscriber privileges or above, to change the order of posts in the posts menu.
- CVSS:
- 4.3
- Affected:
- up to 3.1.3
- Fixed in:
- 3.1.4
- Disclosed:
- Jan 24, 2023
CVE-2022-4385 on NVD →
Intuitive Custom Post Order <= 3.1.3 - Cross-Site Request Forgery
medium
The Intuitive Custom Post Order plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.3. This is due to missing or incorrect nonce validation on the update-menu-order AJAX action. This makes it possible for unauthenticated attackers to update the order of menu items, via...
- CVSS:
- 4.3
- Affected:
- up to 3.1.3
- Fixed in:
- 3.1.4
- Disclosed:
- Jan 24, 2023
CVE-2022-4386 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database