4.3
CVSSv3

CVE-2022-4385

Published: 21/02/2023 Updated: 07/11/2023
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The Intuitive Custom Post Order WordPress plugin prior to 3.1.4 does not check for authorization in the update-menu-order ajax action, allowing any logged in user (with roles as low as Subscriber) to update the menu order

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

intuitive custom post order project intuitive custom post order