CVE-2025-32236 MEDIUM

CVE-2025-32236: WordPress Woocommerce Products Reorder Drag Drop Multiple Sort plugin <= 1.9 - Broken Access Control vulnerability

Vendor Vagonic
Product Woocommerce Products Reorder Drag Drop Multiple Sort – Sortable, Rearrange Products Vagonic
Weakness CWE-862 · Missing authorization
Published April 10, 2025
Last update April 28, 2026

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

Missing Authorization vulnerability in Vagonic Woocommerce Products Reorder Drag Drop Multiple Sort – Sortable, Rearrange Products Vagonic vagonic-sortable.This issue affects Woocommerce Products Reorder Drag Drop Multiple Sort – Sortable, Rearrange Products Vagonic: from n/a through <= 1.9.

Explanation of Vulnerability in Simple Terms

02Summary

The Woocommerce Products Reorder Drag Drop Multiple Sort plugin for WordPress contains a missing authorization check that allows authenticated users with low privileges to modify product sort order without proper permission validation. An attacker with a basic user account can change the order of products in the store. The vulnerability affects versions 0 through 1.9. Update to a version newer than 1.9 when available.

What an attacker can do

03Attacker Capabilities

Modify the sort order of WooCommerce products without proper authorization.

Potential impact on your site

04Site Impact

Unauthorized users can rearrange your product listings, potentially disrupting customer experience and sales.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege authenticated account on the WordPress site.

Key dates

06Disclosure timeline

April 10, 2025 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE