What the vulnerability does
01Description
Missing Authorization vulnerability in Fahad Mahmood WP Sort Order.This issue affects WP Sort Order: from n/a through 1.3.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Fahad Mahmood WP Sort Order.This issue affects WP Sort Order: from n/a through 1.3.1.
Explanation of Vulnerability in Simple Terms
WP Sort Order through version 1.3.1 lacks proper authorization checks, allowing authenticated users with low privileges to modify sort order settings they should not have access to. The vulnerability requires a valid WordPress account but does not require administrator rights. An attacker can alter site sorting behavior through direct API calls or form manipulation.
What an attacker can do
Modify sort order settings on the site without proper authorization.
Potential impact on your site
Unauthorized users can change how content is sorted, potentially disrupting site functionality or user experience.
Conditions required to exploit
Attacker must have a valid WordPress user account with low-level privileges.
Key dates
External resources
Related vulnerabilities