Known vulnerabilities in WP Sort Order
Order terms (Users, Posts, Pages, Custom Post Types and Custom Taxonomies) using a Drag and Drop with jQuery ui Sortable.
2Reported vulnerabilities
5.3Highest CVSS score
1.3.5Latest version
6,000+Active installs
What to do now
Update WP Sort Order to 1.3.2 or later.
1 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2026-28567 | Medium | 0.3% | 1.3.5 and earlier | — | August 14, 2026 |
| CVE-2024-31294 | Medium | 0.3% | 1.3.1 and earlier | 1.3.2 |
April 5, 2024 |