The Intuitive Custom Post Order Project is a narrowly scoped WordPress plugin focused on order-management customization, with observed vulnerabilities centered on access-control and request-validation weaknesses. Its disclosed exposure recurs through cross-site request forgery and missing-authorization issues, typical of plugin-tier functionality gaps in permission enforcement and state-change protection.
The number and severity of CVEs published that impact products developed by Intuitive Custom Post Order Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-4386MEDIUM The Intuitive Custom Post Order WordPress plugin before 3.1.4 lacks CSRF protection in its update-menu-order ajax action, allowing an attacker to trick any user to change the menu | Feb 21, 2023 | 4.3 | 17 | NO | NO |
CVE-2022-4385MEDIUM The Intuitive Custom Post Order WordPress plugin before 3.1.4 does not check for authorization in the update-menu-order ajax action, allowing any logged in user (with roles as low | Feb 21, 2023 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Intuitive Custom Post Order Project.
Media articles that mention a CVE ID that affects a product developed by Intuitive Custom Post Order Project — matched by CVE ID, not by vendor name.