Description
Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions.
Published: 2026-08-18
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability stems from a broken access control mechanism in the WP Sort Order plugin. The flaw permits unauthenticated actors to perform operations reserved for privileged users, potentially allowing them to modify, delete, or otherwise tamper with content managed by the plugin. The weakness corresponds to CWE‑862, which addresses improper authorization controls.

Affected Systems

The issue affects all WordPress sites running the WP Sort Order plugin version 1.3.5 or earlier, distributed by Fahad Mahmood. Users deploying these versions are exposed to the risk.

Risk and Exploitability

The CVSS score of 7.5 signals a high impact vulnerability, though its EPSS score is currently unavailable and it is not listed in the CISA KEV catalog. Likely, an attacker can exploit the flaw remotely, without authentication, by crafting requests to the plugin’s endpoints. The lack of known exploit data suggests no public exploit code exists yet, but the combination of remote reach and unauthenticated access makes it a credible target for attackers seeking to compromise site integrity.

Generated by OpenCVE AI on August 18, 2026 at 15:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to WP Sort Order plugin version 1.3.6 or later, which addresses the access control issue.
  • If upgrading is not immediately possible, disable the plugin on the production site to eliminate exposure.
  • Apply a WordPress role and capability review to restrict non-administrative users from accessing the plugin’s administrative endpoints.

Generated by OpenCVE AI on August 18, 2026 at 15:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions.
Title WordPress WP Sort Order plugin <= 1.3.5 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-18T13:59:03.244Z

Reserved: 2026-03-02T16:05:30.326Z

Link: CVE-2026-28567

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T14:17:02.327

Modified: 2026-08-18T14:17:02.327

Link: CVE-2026-28567

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T15:30:05Z

Weaknesses