NA

CVE-2022-4386

Published: 21/02/2023 Updated: 07/11/2023
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The Intuitive Custom Post Order WordPress plugin prior to 3.1.4 lacks CSRF protection in its update-menu-order ajax action, allowing an malicious user to trick any user to change the menu order via a CSRF attack

Vulnerable Product Search on Vulmon Subscribe to Product

intuitive custom post order project intuitive custom post order