| |
Vulnerability CVE-2022-4385
Published: 2023-02-21
| Description: |
The Intuitive Custom Post Order WordPress plugin through 3.1.3 does not check for authorization in the update-menu-order ajax action, allowing any logged in user (with roles as low as Subscriber) to update the menu order |
Type:
CWE-862 (Missing Authorization)
References: |
https://wpscan.com/vulnerability/8f900d37-6eee-4434-8b9b-d10cc4a9167c
|
|
|
closedb();
?>
Copyright 2026, cxsecurity.com
|
|
|