
CVE-2026-1378 The WP Posts Re-order plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validatio… https://www.cve.org/CVERecord?id=CVE-2026-1378
Post summary
The post announces a CSRF vulnerability in the WP Posts Re‑order WordPress plugin (CVE‑2026‑1378) caused by missing nonce validation, with no additional details on PoC, exploitation, or remediation.
