ZeroHour

CVE-2022-4385

PoC
CVSS 3.1
4.3 medium
EPSS
<1%p41
Published
()
Modified
Description

The Intuitive Custom Post Order WordPress plugin before 3.1.4 does not check for authorization in the update-menu-order ajax action, allowing any logged in user (with roles as low as Subscriber) to update the menu order

Vendors
intuitive custom post order project
Products
intuitive custom post order
Ecosystems
WordPress
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.