CVE-2026-28567: WordPress WP Sort Order plugin <= 1.3.5 - Broken Access Control vulnerability
Published Aug 18, 2026
·Updated
Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions.
Affected Software
1 affected component
wp-sort-order<=1.3.5
Event History
Aug 18, 2026
CVE Published
via MITRE·01:59 PM
Data Sourced
via MITRE·01:59 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are affected?
Sites running WP Sort Order version 1.3.5 or earlier are identified as affected. The provided data does not state whether a fixed version is available.
2
What does an attacker need to exploit this issue?
The vulnerability is unauthenticated and has network attack vector, so an attacker does not need an account or user interaction to attempt exploitation remotely.
3
What is the expected impact of successful exploitation?
The listed impact is high confidentiality impact, with no integrity or availability impact specified. The provided data does not identify which data or functions may be exposed.