WP Posts Re-order - Cross-Site Request Forgery to Settings Update vulnerability
mediumCross-Site Request Forgery to Settings Update vulnerability
- CVSS:
- 4.3
- Affected:
- up to 1.0
- Fix:
- No patched version reported
- Disclosed:
- Mar 23, 2026
plugin
2 known security issues reported for the Wp Posts Re Order WordPress plugin. Most recent disclosed Mar 23, 2026.
Running Wp Posts Re Order on your site? Check whether your installed version is affected.
Scan your site freeCross-Site Request Forgery to Settings Update vulnerability
The WP Posts Re-order plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on the `cpt_plugin_options()` function. This makes it possible for unauthenticated attackers to update the plugin settings including capability, autos...
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free