Simple Page Ordering

Simple Page Ordering has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2023; all 4 are fixed as of September 2026. Their average CVSS score is 4.5, and the most serious one scores 5.4 out of 10. 2022 was the busiest year with 3 disclosures.

The most common weakness is Uncontrolled Resource Consumption, behind 2 of the records (50%). Other recurring categories include Missing Authorization, Open Redirect.

Every one of the 4 issues recorded for Simple Page Ordering has a vendor fix available, so running the current release closes all known holes.

All of these findings were reported by Kévin Mosbahi (Mika). Simple Page Ordering is installed on roughly 100,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
4.5/ 10
Patch Coverage100%
Open

0

Fixed

4

Get automatic notifications for all Simple Page Ordering vulnerabilities before they are exploited.

Highest severity on recordCVSS 5.4CVE-2023-32798

Simple Page Ordering <= 2.5.0 - Missing Authorization to Information Disclosure

Read the full analysis

Vulnerability Records

4 records
Simple Page Ordering banner
Latestv2.8.0

Simple Page Ordering

10up

Author

10up

4.7(131)
94/100
Last Updated
2026-09-01 (11d ago)
Active Installs
100,000+
Downloads
4,375,754
Requires WP
6.8+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2010-08-21 (16y ago)

Order your pages, hierarchical custom post types, or custom post types with “page-attributes” with drag and drop right from the built in page list. Drag and drop the page into the desired position. No new admin menus pages, no clunky, bolted on user interfaces. Drag and drop on the page or post-type screen. The plug-in is “capabilities aware” – only users with the ability to edit others’ pages (editors and administrators) will be able to reorder content. Integrated help is included: click the “help” tab at the top right of the screen. Please note that the plug-in is not compatible with Internet Explorer 7 and earlier, due to limitations within those browsers. Contributing We’d love to have you join in on development over on GitHub.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C