Impact
This vulnerability stems from a broken access control mechanism in the WP Sort Order plugin. The flaw permits unauthenticated actors to perform operations reserved for privileged users, potentially allowing them to modify, delete, or otherwise tamper with content managed by the plugin. The weakness corresponds to CWE‑862, which addresses improper authorization controls.
Affected Systems
The issue affects all WordPress sites running the WP Sort Order plugin version 1.3.5 or earlier, distributed by Fahad Mahmood. Users deploying these versions are exposed to the risk.
Risk and Exploitability
The CVSS score of 7.5 signals a high impact vulnerability, though its EPSS score is currently unavailable and it is not listed in the CISA KEV catalog. Likely, an attacker can exploit the flaw remotely, without authentication, by crafting requests to the plugin’s endpoints. The lack of known exploit data suggests no public exploit code exists yet, but the combination of remote reach and unauthenticated access makes it a credible target for attackers seeking to compromise site integrity.
OpenCVE Enrichment