Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Intuitive Custom Post Order Project Subscribe
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-4385 1 Intuitive Custom Post Order Project 1 Intuitive Custom Post Order 2023-02-27 N/A 4.3 MEDIUM
The Intuitive Custom Post Order WordPress plugin before 3.1.4 does not check for authorization in the update-menu-order ajax action, allowing any logged in user (with roles as low as Subscriber) to update the menu order
CVE-2022-4386 1 Intuitive Custom Post Order Project 1 Intuitive Custom Post Order 2023-02-27 N/A 4.3 MEDIUM
The Intuitive Custom Post Order WordPress plugin before 3.1.4 lacks CSRF protection in its update-menu-order ajax action, allowing an attacker to trick any user to change the menu order via a CSRF attack