CloudSearch

CloudSearch has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).

The one issue recorded for CloudSearch has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.

All of these findings were reported by Nguyen Xuan Chien. CloudSearch is installed on roughly 60 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 5.9.16.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage0%
Open

1

Fixed

0

Get automatic notifications for all CloudSearch vulnerabilities before they are exploited.

Most severe open issueCVSS 4.3CVE-2025-62962

CloudSearch <= 3.0.0 - Cross-Site Request Forgery

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
CloudSearch banner
Latestv3.0.0
5.0(5)
100/100
Last Updated
2023-01-27 (4y ago)
Active Installs
60+
Downloads
9,184
Requires WP
4.4+
Requires PHP
0+
Tested up to
WP 5.9.16
Created
2016-02-14 (11y ago)

CloudSearch is a flexible plugin that allows you to leverage the search index power of Amazon CloudSearch in your WordPress site. To use this plugin you’ll need an Amazon Web Services account. Attention: Amazon CloudSearch is a paid service and will require a credit card. Before you can start using CloudSearch, the plugin needs to be activated and configured. Activate the plugin, then go to the menu “CloudSearch -> Settings” (you can find this menu in the sidebar of your WordPress admin panel). Fill the form data: Enter Amazon access key ID, Amazon secret access key and Amazon region for your account (look for “Security Credentials” in your Amazon console to retrieve these data) Enter your CloudSearch index search endpoint and the domain name (I suggest to create the CloudSearch index before you start the plugin configuration) Schema settings Other settings IMPORTANT NOTES WITH RELEASE 2.0.0: * At least WordPress 4.4 version mandatory (for WP_Term support) * Changed APIs output from an array of IDs to an array of object composed by the entity ID and the entity type Minimum requirements: WordPress Version 4.4 PHP Version 5.3 Amazon Web Services account with CloudSearch enabled Usage Go to CloudSearch -> Settings Enter your Amazon access key ID, Secret access key and the Amazon region where you have created the CloudSearch index Enter a Search endpoint and the Domain name. Get these info in your CloudSearch dashboard in AWS Console Choose post types, custom fields and custom taxonomies that you want to export to the CloudSearch index Set up other settings or leave defaults Save settings. Go to CloudSearch -> Manage Click the action Create index, Run indexing and Sync all documents. Between every action wait until the Status field is Active, then go on with the next task After these operation your index is ready, now you can search documents in your CloudSearch index Links: Author’s Site

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C