{"error":0,"message":null,"data":{"name":"Category Order and Taxonomy Terms Order","plugin":"taxonomy-terms-order","link":"https:\/\/wordpress.org\/plugins\/taxonomy-terms-order\/","latest":"1786975620","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"1cf2bd5b551fb2da82521dbf5d4afd3ee59947cceaf613f0c3d763a9c7de8d1f","name":"Category Order and Taxonomy Terms Order [taxonomy-terms-order] < 1.5.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.5.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"d986c14e00508b6c826b4b953e870e8a2c161a1e","name":"WordPress Category Order and Taxonomy Terms Order plugin <=1.5.2.2 - Authenticated PHP Object Injection vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/taxonomy-terms-order\/vulnerability\/wordpress-category-order-and-taxonomy-terms-order-plugin-1-5-2-2-authenticated-php-object-injection-vulnerability","description":"Authenticated PHP Object Injection vulnerability found in WordPress Category Order and Taxonomy Terms Order plugin (versions <=1.5.2.2).","date":"2018-03-02"}],"impact":[]},{"uuid":"c3e3b8a3c24883298b4dcbcbdc3f81c93498159c90825adb2e5b521644d34c01","name":"Category Order and Taxonomy Terms Order [taxonomy-terms-order] < 1.4.6.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.4.6.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"1574ceff6315568f1a28d9f7ef97173437f6805d","name":"WordPress Category Order and Taxonomy Terms Order Plugin <= 1.4.4 - XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/taxonomy-terms-order\/vulnerability\/wordpress-category-order-and-taxonomy-terms-order-plugin-1-4-4-xss","description":"Because of this vulnerability, authenticated administrators can inject HTML and JS code.\nUpdate the plugin.","date":"2015-08-18"}],"impact":[]},{"uuid":"b6726ff5b2f9adccf8a17ca6a968380193001b9fa603c4ab7414a8e6fe54cedd","name":"Category Order and Taxonomy Terms Order [taxonomy-terms-order] < 1.5.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.5.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"38f9e0fec8b73857bdde8087f2f0aab4aeb32494","name":"Category Order and Taxonomy Terms Order <= 1.5.2.2 - Authenticated PHP Object Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/taxonomy-terms-order\/category-order-and-taxonomy-terms-order-1522-authenticated-php-object-injection","description":"The Category Order and Taxonomy Terms Order plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.2.2 via deserialization of untrusted input from the 'order' parameter. This allows authenticated attackers, with subscriber-level permissions and above, to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.","date":"2018-02-22"}],"impact":[]},{"uuid":"49a503e17929851d9d12e6cf63798e03e8d8cdeac38f6afa630e16a4c2efbbdc","name":"Category Order and Taxonomy Terms Order [taxonomy-terms-order] < 1.4.6.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.4.6.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"9b4ca0bd5d20c0b4937b59a97ba6e251e6cf7d49","name":"Category Order and Taxonomy Terms Order <1.4.6.0 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/taxonomy-terms-order\/category-order-and-taxonomy-terms-order-1460-cross-site-scripting","description":"The Category Order and Taxonomy Terms Order plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.4.6.0 due to insufficient input sanitization and output escaping on the 'post_type' parameter. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.","date":"2015-08-18"}],"impact":[]},{"uuid":"0d1e2fe9ff1596eef33937b31b58bdb35a085bca167143328b530dc8cff351d3","name":"Category Order and Taxonomy Terms Order [taxonomy-terms-order] < 1.5.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.5.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"93c2e853-94f7-4dba-b2b4-d529cca89812","name":"Category Order and Taxonomy Terms Order &lt;= 1.5.2.2 - Authenticated PHP Object Injection","link":"https:\/\/wpscan.com\/vulnerability\/93c2e853-94f7-4dba-b2b4-d529cca89812","description":"Usage of unserialize() on user input in the saving request of the orders leads to PHP object injection vulnerability.","date":null}],"impact":[]},{"uuid":"df413e87f86cc2fd2623f1e33e9a20921b33e81b6280423584af797f15473510","name":"Category Order and Taxonomy Terms Order [taxonomy-terms-order] < 1.4.6.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.4.6.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"16c77cfc-e1ca-4833-b5a2-01612eb646e2","name":"Category Order &amp; Taxonomy Terms Order &lt;= 1.4.4 - Authenticated Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/16c77cfc-e1ca-4833-b5a2-01612eb646e2","description":"The Category Order and Taxonomy Terms Order WordPress plugin was affected by an Authenticated Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":[]}]},"updated":"1776153795"}