Intuitive Custom Post Order
Intuitive Custom Post Order has 4 disclosed vulnerabilities in the WordSec catalog, all reported in 2023; all 4 are fixed as of September 2026. Their average CVSS score is 4.9, and the most serious one scores 6.6 out of 10. 2023 was the busiest year with 4 disclosures.
The most common weakness is Missing Authorization, behind 2 of the records (50%). Other recurring categories include Cross-Site Request Forgery (CSRF), SQL Injection.
Every one of the 4 issues recorded for Intuitive Custom Post Order has a vendor fix available, so running the current release closes all known holes.
All of these findings were reported by Yuya Kotake. Intuitive Custom Post Order is installed on roughly 400,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2023-1016Intuitive Custom Post Order <= 3.1.4.1 - Authenticated (Admin+) SQL Injection
Read the full analysisVulnerability Records

Intuitive Custom Post Order
Author
hijiri
Intuitively reorder Posts, Pages, Custom Post Types, Taxonomies, and Sites with a simple drag-and-drop interface. Intuitive Custom Post Order lets you reorder items with simple drag and drop in the WordPress admin. You can sort Posts, Pages, Custom Post Types, Taxonomies, and (on Multisite) Sites. Go to Settings → Intuitive CPO and select which content types you want to make sortable. Once enabled, just drag and drop items in the list tables—no extra setup is required. If you create custom queries in your theme or plugins, set orderby=menu_order and order=ASC to respect the drag-and-drop order. To keep the default WordPress order (by date), explicitly set orderby=date and order=DESC. Source code and development are available on GitHub.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C