plugin

Intuitive Custom Post Order Vulnerabilities

4 known security issues reported for the Intuitive Custom Post Order WordPress plugin. Most recent disclosed Jan 25, 2023.

4 medium

Running Intuitive Custom Post Order on your site? Check whether your installed version is affected.

Scan your site free

Intuitive Custom Post Order <= 3.1.4.1 - Authenticated (Admin+) SQL Injection

medium

The Intuitive Custom Post Order plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.1.4.1, due to insufficient escaping on the user supplied 'objects' and 'tags' parameters and lack of sufficient preparation in the 'update_options' function as well as the 'refresh' function which run...

CVSS:
6.6
Affected:
up to 3.1.4
Fixed in:
3.1.5
Disclosed:
Jan 25, 2023

CVE-2023-1016 on NVD →

Intuitive Custom Post Order <= 3.1.3 - Missing Authorization to Authenticated Settings Change

medium

The Intuitive Custom Post Order plugin for WordPress is vulnerable to authenticated settings change in versions up to and including 3.1.3 via the 'update-menu-order-sites' AJAX action. This allows authenticated attackers with subscriber privileges or above, to change the order of sites in the sites menu on multisite in...

CVSS:
4.3
Affected:
up to 3.1.3
Fixed in:
3.1.4
Disclosed:
Jan 25, 2023

Intuitive Custom Post Order <= 3.1.3 - Missing Authorization to Authenticated Settings Change

medium

The Intuitive Custom Post Order plugin for WordPress is vulnerable to authenticated settings change in versions up to and including 3.1.3 via the 'update-menu-order' AJAX action. This allows authenticated attackers with subscriber privileges or above, to change the order of posts in the posts menu.

CVSS:
4.3
Affected:
up to 3.1.3
Fixed in:
3.1.4
Disclosed:
Jan 24, 2023

CVE-2022-4385 on NVD →

Intuitive Custom Post Order <= 3.1.3 - Cross-Site Request Forgery

medium

The Intuitive Custom Post Order plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.3. This is due to missing or incorrect nonce validation on the update-menu-order AJAX action. This makes it possible for unauthenticated attackers to update the order of menu items, via...

CVSS:
4.3
Affected:
up to 3.1.3
Fixed in:
3.1.4
Disclosed:
Jan 24, 2023

CVE-2022-4386 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database