CVE-2022-4386

CVSS V2 None CVSS V3 None
Description
The Intuitive Custom Post Order WordPress plugin before 3.1.4 lacks CSRF protection in its update-menu-order ajax action, allowing an attacker to trick any user to change the menu order via a CSRF attack
Overview
  • CVE ID
  • CVE-2022-4386
  • Assigner
  • contact@wpscan.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-02-21T09:15:10
  • Last Modified Date
  • 2023-02-28T02:22:49
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:intuitive_custom_post_order_project:intuitive_custom_post_order:*:*:*:*:*:wordpress:*:* 1 OR 3.1.4
References
Reference URL Reference Tags
https://wpscan.com/vulnerability/734064e3-afe9-4dfd-8d76-8a757cc94815 Exploit Third Party Advisory
History
Created Old Value New Value Data Type Notes
2023-04-17 08:01:06 Added to TrackCVE
2023-04-17 08:01:08 Weakness Enumeration new