The SearchWP Live Ajax Search WordPress plugin before 1.6.2 does not ensure that users making a live search are limited to published posts only, allowing unauthenticated users to make a crafted query disclosing private/draft/pending post titles along with their permalink
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/0e13c375-044c-4c2e-ab8e-48cb89d90d02 | Exploit Third Party Advisory |
https://wpscan.com/vulnerability/0e13c375-044c-4c2e-ab8e-48cb89d90d02 | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 07:01
Type | Values Removed | Values Added |
---|---|---|
References | () https://wpscan.com/vulnerability/0e13c375-044c-4c2e-ab8e-48cb89d90d02 - Exploit, Third Party Advisory |
16 Aug 2022, 16:16
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://wpscan.com/vulnerability/0e13c375-044c-4c2e-ab8e-48cb89d90d02 - Exploit, Third Party Advisory | |
CPE | cpe:2.3:a:searchwp:searchwp_live_ajax_search:*:*:*:*:*:wordpress:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
15 Aug 2022, 11:21
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-08-15 11:21
Updated : 2024-11-21 07:01
NVD link : CVE-2022-2535
Mitre link : CVE-2022-2535
CVE.ORG link : CVE-2022-2535
JSON object : View
Products Affected
searchwp
- searchwp_live_ajax_search
CWE
CWE-639
Authorization Bypass Through User-Controlled Key