Unauthenticated Access Control Flaw in WP Sort Order by WordPress
CVE-2026-28567

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 August 2026

What is CVE-2026-28567?

The WP Sort Order plugin prior to version 1.3.6 has a vulnerability that allows unauthenticated users to exploit broken access controls. This issue can lead to unauthorized manipulation of sorting functionalities without the need for user authentication, posing a risk to site integrity. It is essential for users of the plugin to update to the latest version to mitigate potential unauthorized access.

Affected Version(s)

WP Sort Order <= 1.3.5

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hhhai | Patchstack Bug Bounty Program
.