Search Exclude

Search Exclude has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2019 and 2025; all 4 are fixed as of September 2026. Their average CVSS score is 5.7, and the most serious one scores 7.5 out of 10. Severity breakdown: 0 critical and 1 high. 2025 was the busiest year with 2 disclosures.

The most common weakness is Missing Authorization, behind 3 of the records (75%). Other recurring categories include Cross-Site Scripting.

Every one of the 4 issues recorded for Search Exclude has a vendor fix available, so running the current release closes all known holes.

4 independent researchers contributed these findings, one record each. Search Exclude is installed on roughly 50,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
5.7/ 10
Patch Coverage100%
Open

0

Fixed

4

Get automatic notifications for all Search Exclude vulnerabilities before they are exploited.

Highest severity on recordCVSS 7.5CVE-2019-15895

Search Exclude <= 1.2.3 - Arbitrary Settings Change

Read the full analysis

Vulnerability Records

4 records
Search Exclude banner
Latestv2.6.6

Search Exclude

quadlayers

Author

quadlayers

4.8(217)
96/100
Last Updated
2026-08-24 (19d ago)
Active Installs
50,000+
Downloads
2,178,276
Requires WP
4.7+
Requires PHP
5.6+
Tested up to
WP 7.1
Created
2012-12-06 (14y ago)

With this plugin you can exclude any page, post or whatever from the WordPress search results by checking off the corresponding checkbox on post/page edit page. Supports quick and bulk edit. On the plugin settings page you can also see the list of all the items that are hidden from search. Presentation QuadLayers | Community

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C