Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2636▼ 301 respecto a la semana anterior
Críticas / altas1352▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
3 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.97% | — | Hijiriworld Intuitive Custom Post Order | 9/6/2023 | 17/6/2026 | The Intuitive Custom Post Order plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.1.4.1, due to insufficient escaping on the user supplied 'objects' and 'tags' parameters and lack of sufficient preparation in the 'update_options' function as well as the 'refresh' function which… | |
| Modificada | Media (4.3) | 0.27% | — | Intuitive Custom Post Order Project Intuitive Custom Post Order | 21/2/2023 | 17/6/2026 | The Intuitive Custom Post Order WordPress plugin before 3.1.4 lacks CSRF protection in its update-menu-order ajax action, allowing an attacker to trick any user to change the menu order via a CSRF attack | |
| Modificada | Media (4.3) | 0.49% | — | Intuitive Custom Post Order Project Intuitive Custom Post Order | 21/2/2023 | 17/6/2026 | The Intuitive Custom Post Order WordPress plugin before 3.1.4 does not check for authorization in the update-menu-order ajax action, allowing any logged in user (with roles as low as Subscriber) to update the menu order |