The Intuitive Custom Post Order WordPress plugin before 3.1.4 does not check for authorization in the update-menu-order ajax action, allowing any logged in user (with roles as low as Subscriber) to update the menu order
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://wpscan.com/vulnerability/8f900d37-6eee-4434-8b9b-d10cc4a9167c | exploit vdb entry third party advisory technical description |