Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Intuitive Custom Post Order Project Subscribe
Filtered by product Intuitive Custom Post Order
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-4385 1 Intuitive Custom Post Order Project 1 Intuitive Custom Post Order 2023-02-27 N/A 4.3 MEDIUM
The Intuitive Custom Post Order WordPress plugin before 3.1.4 does not check for authorization in the update-menu-order ajax action, allowing any logged in user (with roles as low as Subscriber) to update the menu order
CVE-2022-4386 1 Intuitive Custom Post Order Project 1 Intuitive Custom Post Order 2023-02-27 N/A 4.3 MEDIUM
The Intuitive Custom Post Order WordPress plugin before 3.1.4 lacks CSRF protection in its update-menu-order ajax action, allowing an attacker to trick any user to change the menu order via a CSRF attack