{"error":0,"message":null,"data":{"name":"Intuitive Custom Post Order","plugin":"intuitive-custom-post-order","link":"https:\/\/wordpress.org\/plugins\/intuitive-custom-post-order\/","latest":"1757993820","closed":1,"closed_reason":"unknown","closed_date":null,"vulnerability":[{"uuid":"6d57087e848ca938ce85869eb23f769c2f2e8fd7adecf7b77566f8c660ab6b02","name":"Intuitive Custom Post Order [intuitive-custom-post-order] < 3.1.4 (closed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.4","max_operator":"lt","unfixed":"0","closed":"1"},"source":[{"id":"380e8535297417013cf4c7f69aeac18c10b8284b","name":"Intuitive Custom Post Order <= 3.1.3 - Missing Authorization to Authenticated Settings Change","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/intuitive-custom-post-order\/intuitive-custom-post-order-313-missing-authorization-to-authenticated-settings-change-3","description":"The Intuitive Custom Post Order plugin for WordPress is vulnerable to authenticated settings change in versions up to and including 3.1.3 via the 'update-menu-order-sites' AJAX action. This allows authenticated attackers with subscriber privileges or above, to change the order of sites in the sites menu on multisite installations.","date":"2023-01-25"}],"impact":[]},{"uuid":"f308c7c17b8347209eda49d7f1a2cdfde5f3603c261fb58d951e2411fd6f502a","name":"Intuitive Custom Post Order [intuitive-custom-post-order] < 3.1.4 (closed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.4","max_operator":"lt","unfixed":"0","closed":"1"},"source":[{"id":"CVE-2022-4385","name":"CVE-2022-4385","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-4385","description":"[en] The Intuitive Custom Post Order WordPress plugin before 3.1.4 does not check for authorization in the update-menu-order ajax action, allowing any logged in user (with roles as low as Subscriber) to update the menu order","date":"2023-02-21"},{"id":"8de0a3a6d6b25ee3c727fa22fe352c44faa49e6a","name":"Intuitive Custom Post Order <= 3.1.3 - Missing Authorization to Authenticated Settings Change","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/intuitive-custom-post-order\/intuitive-custom-post-order-313-missing-authorization-to-authenticated-settings-change-2","description":"The Intuitive Custom Post Order plugin for WordPress is vulnerable to authenticated settings change in versions up to and including 3.1.3 via the 'update-menu-order' AJAX action. This allows authenticated attackers with subscriber privileges or above, to change the order of posts in the posts menu.","date":"2023-01-24"},{"id":"0d43b9ef3c62ceb029c4895af90294151a6b25e5","name":"WordPress  Intuitive Custom Post Order Plugin  <= 3.1.3 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/intuitive-custom-post-order\/vulnerability\/wordpress-intuitive-custom-post-order-plugin-3-1-3-subscriber-broken-access-control-vulnerability","description":"Deactivate and delete. This plugin has been closed as of January 18, 2023 and is not available for download. This closure is temporary, pending a full review.\nYuya Kotake  discovered and reported this Broken Access Control vulnerability in WordPress Intuitive Custom Post Order Plugin.  This vulnerability has not been known to be fixed yet.","date":"2023-01-24"},{"id":"8f900d37-6eee-4434-8b9b-d10cc4a9167c","name":"Intuitive Custom Post Order &lt; 3.1.4 - Subscriber+ Arbitrary Menu Order Update","link":"https:\/\/wpscan.com\/vulnerability\/8f900d37-6eee-4434-8b9b-d10cc4a9167c","description":"The plugin does not check for authorization in the update-menu-order ajax action, allowing any logged in user (with roles as low as Subscriber) to update the menu order","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"7c959d2053be5038fa98231e81da7f12cccb0882d70e64b601f582d13ec51dea","name":"Intuitive Custom Post Order [intuitive-custom-post-order] <= 3.1.3 (unfixed + closed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.3","max_operator":"le","unfixed":"1","closed":"1"},"source":[{"id":"fb854943a69160d6e51117be558eee05e1b4c200","name":"404 Page Not Found","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/intuitive-custom-post-order\/intuitive-custom-post-order-313-missing-authorization-to-authenticated-settings-change","description":"","date":null}],"impact":[]},{"uuid":"f37385aff2121b830562a7446b92e67de2eb4b94cc1402d6066da4fdec6bcb16","name":"Intuitive Custom Post Order [intuitive-custom-post-order] < 3.1.4 (closed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.4","max_operator":"lt","unfixed":"0","closed":"1"},"source":[{"id":"CVE-2022-4386","name":"CVE-2022-4386","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-4386","description":"[en] The Intuitive Custom Post Order WordPress plugin before 3.1.4 lacks CSRF protection in its update-menu-order ajax action, allowing an attacker to trick any user to change the menu order via a CSRF attack","date":"2023-02-21"},{"id":"f8a2506d9c537f9ff241c98151d2edaf31542cca","name":"Intuitive Custom Post Order <= 3.1.3 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/intuitive-custom-post-order\/intuitive-custom-post-order-313-cross-site-request-forgery","description":"The Intuitive Custom Post Order plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.3. This is due to missing or incorrect nonce validation on the update-menu-order AJAX action. This makes it possible for unauthenticated attackers to update the order of menu items, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-01-24"},{"id":"693a67f1194cc3a52a6a202b23f0c4510ab7ac2c","name":"WordPress  Intuitive Custom Post Order Plugin  <= 3.1.3 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/intuitive-custom-post-order\/vulnerability\/wordpress-intuitive-custom-post-order-plugin-3-1-3-csrf-vulnerability","description":"Deactivate and delete. This plugin has been closed as of January 18, 2023 and is not available for download. This closure is temporary, pending a full review.\nYuya Kotake discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Intuitive Custom Post Order Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. For example a password change which will then allow the malicious actor to login into the admin account. This vulnerability has not been known to be fixed yet.","date":"2023-01-24"},{"id":"734064e3-afe9-4dfd-8d76-8a757cc94815","name":"Intuitive Custom Post Order &lt; 3.1.4 - Arbitrary Menu Order Update via CSRF","link":"https:\/\/wpscan.com\/vulnerability\/734064e3-afe9-4dfd-8d76-8a757cc94815","description":"The plugin lacks CSRF protection in its update-menu-order ajax action, allowing an attacker to trick any user to change the menu order via a CSRF attack","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"e33f9fedced7bc5a681027e294e5c4313230644279073456145f0354c8b5ca75","name":"Intuitive Custom Post Order [intuitive-custom-post-order] < 3.1.5 (closed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.5","max_operator":"lt","unfixed":"0","closed":"1"},"source":[{"id":"CVE-2023-1016","name":"CVE-2023-1016","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-1016","description":"[en] The Intuitive Custom Post Order plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.1.3, due to insufficient escaping on the user supplied 'objects' and 'tags' parameters and lack of sufficient preparation in the 'update_options' function as well as the 'refresh' function which runs queries on the same values. This allows authenticated attackers, with administrator permissions, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Note that this attack may only be practical on configurations where it is possible to bypass addslashes due to the database using a nonstandard character set such as GBK.","date":"2023-06-09"},{"id":"92409209ae488a68a0a9ac7c4d82c80103dce9f6","name":"Intuitive Custom Post Order <= 3.1.4.1 - Authenticated (Admin+) SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/intuitive-custom-post-order\/intuitive-custom-post-order-313-authenticated-admin-sql-injection","description":"The Intuitive Custom Post Order plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.1.4.1, due to insufficient escaping on the user supplied 'objects' and 'tags' parameters and lack of sufficient preparation in the 'update_options' function as well as the 'refresh' function which runs queries on the same values. This allows authenticated attackers, with administrator permissions, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Note that this attack may only be practical on configurations where it is possible to bypass addslashes due to the database using a nonstandard character set such as GBK.","date":"2023-01-25"},{"id":"00ad48f2-c172-4418-b25b-9068f6af904f","name":"Intuitive Custom Post Order &lt;= 3.1.3 - Administrator SQL Injection","link":"https:\/\/wpscan.com\/vulnerability\/00ad48f2-c172-4418-b25b-9068f6af904f","description":"The plugin does not properly escape user-supplied &#039;objects&#039; and &#039;tags&#039; parameters and lacks sufficient preparation in the &#039;update_options&#039; and &#039;refresh&#039; functions, leading to potential SQL Injection vulnerabilities.","date":null},{"id":"c87fad66b29965391ef4bd0733e67644aeccead0","name":"WordPress  Intuitive Custom Post Order Plugin  <= 3.1.3 is vulnerable to SQL Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/intuitive-custom-post-order\/vulnerability\/wordpress-intuitive-custom-post-order-plugin-3-1-3-authenticated-admin-sql-injection-vulnerability","description":"No patched version available.\nUnknown discovered and reported this SQL Injection vulnerability in WordPress Intuitive Custom Post Order Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information and creating new administrator accounts. This vulnerability has not been known to be fixed yet.","date":"2023-01-26"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"7.2","severity":"h","exploitable":"1.2","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"7.2","severity":"high","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"1.2","impact":"5.9"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}}]},"updated":"1789866007"}