Category Order and Taxonomy Terms Order
Category Order and Taxonomy Terms Order has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2015 and 2018; all 2 are fixed as of September 2026. Their average CVSS score is 7.3, and the most serious one scores 8.5 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include Deserialization Of Untrusted Data.
Every one of the 2 issues recorded for Category Order and Taxonomy Terms Order has a vendor fix available, so running the current release closes all known holes.
All of these findings were reported by Marcin Probola. Category Order and Taxonomy Terms Order is installed on roughly 500,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
Category Order and Taxonomy Terms Order <= 1.5.2.2 - Authenticated PHP Object Injection
Read the full analysisVulnerability Records

Category Order and Taxonomy Terms Order
Author
nsp-code
Easily control the order of Categories and any hierarchical taxonomy with a simple drag-and-drop interface. Reorder parent and child terms visually in the admin and choose whether the plugin automatically applies your custom term order to front-end queries. Key features Intuitive drag-and-drop reordering for Categories and all hierarchical taxonomies. Option to auto-apply the custom term order to front-end queries (no theme/plugin edits required). Keep the admin term lists in your new order (makes management and editorial workflows consistent). Works with multiple taxonomies per post type — switch between taxonomies from the same interface. Multisite aware and regularly updated for modern WordPress and PHP versions (see changelog for compatibility notes). How it works After activating the plugin, a new Taxonomy Order page becomes available under the custom post type menu. Simply open it and drag terms into the exact order you want — including parent/child hierarchy. Use the plugin’s Taxonomy Order screen to drag terms into the order you want. To apply the custom order automatically across your site, enable the Autosort option — the plugin will adjust term queries on the fly so your chosen order shows without template changes. If you prefer to control ordering in code, include orderby => ‘term_order’ when calling get_terms() to use the plugin’s order programmatically. This plugin is developed by Nsp-Code See the Advanced Taxonomy Terms Order for advanced features. Localization Available in Catalan, Chinese (China), Chinese (Taiwan), Czech, Dutch, Dutch (Belgium), English (Australia), English (Canada), English (New Zealand), English (UK), English (US), French (France), Galician, German, Italian, Japanese, Norwegian (Bokmål), Polish, Portuguese (Portugal), Russian, Spanish (Chile), Spanish (Spain), Spanish (Venezuela), Swedish, and Turkish. Whant to contribute with a translation to your language? Please check at https://translate.wordpress.org/projects/wp-plugins/taxonomy-terms-order There isn’t any Editors for your native language on plugin Contributors? You can help to moderate! https://translate.wordpress.org/projects/wp-plugins/taxonomy-terms-order/contributors
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C