Improved user search in backend
Improved user search in backend has one disclosed vulnerability in the WordSec catalog, all reported in 2014; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Improved user search in backend has a vendor fix available, so running the current release closes it.
All of these findings were reported by Mallory Adams. Improved user search in backend is installed on roughly 200 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 3.9.40.
CVE-2014-5196Improved User Search in Backend <= 1.2.5 - Cross-Site Request Forgery to Cross-Site Scripting
Read the full analysisVulnerability Records
Improved user search in backend
Author
Blackbam
This Plugin improves the search for users in the WordPress backend significantly. It empowers admins to search for the first name, last name and email address of users instead of only their nicknames/nicenames. It is also possible to search for custom user meta fields now. Translations: English, German, Swedish Plugin Homepage: http://www.blackbam.at/blackbams-blog/2011/06/27/wordpress-improved-user-search-first-name-last-name-email-in-backend/ Special characters like quotes are escaped, problems with the query may apper when trying to search for other non-alphanumeric characters. 1.2.4 Added translations and il8n (Mikael Grön jag@mikaelgron.se) (en_US, en_UK,sv_SE) Added german translation (de_DE) 1.2.3 Database compatibility improved. 1.2.2 Re-allowed special characters in keys, but strings are still escaped for safe queries. 1.2.1 Filter and test custom meta fields. Remove unallowed characters. 1.2.0 Added Case-insensitive matching. Added Multisite support. 1.1.2 Fix issue where attempting to activate the plugin would throw an “Invalid Header” error 1.1.1 Minor changes. 1.1 Added options page to include custom user meta fields in the search. 1.0.1 Little code improvements. 1.0 Initial release to the Plugins directory.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C