Junglewise Threat Intelligence

CVE-2026-28567: WordPress WP Sort Order broken access control

CVE-2026-28567 · Severity: high · CVSS 7.5 · Published 2026-08-18

Executive brief

WP Sort Order is a WordPress plugin that allows administrators to customize page and post ordering. This vulnerability enables unauthenticated attackers to bypass access controls and perform actions or view data they should not have permission to access, potentially exposing sensitive site information or allowing unauthorized modifications to content ordering.

Technical details

This vulnerability is a broken access control flaw in the WP Sort Order plugin (versions ≤ 1.3.5) that allows unauthenticated users to access protected functionality without proper authorization checks. The vulnerability enables attackers to perform administrative actions or access restricted data without authentication. The attack requires only network access to the WordPress installation and no prior authentication or user interaction. Affected versions are ≤ 1.3.5; the fix is available in version 1.3.6 and later.

Affected products

  • WP Sort Order WP Sort Order ≤ 1.3.5

Timeline

  • 2026-08-18: disclosed
  • 2026-08-14: patched: Patched in version 1.3.6

References