SearchWP Live Ajax Search <= 1.6.1 - Sensitive Information Disclosure
2022-07-25 00:00
Angelo DelicatoStrategic Overview
StatusPatched in 1.6.2
Affected PluginSearchWP Live Ajax Search
Affected Version
<= 1.6.1CVSS5.3Medium
CVE
CVE-2022-2535Vulnerability Overview
The SearchWP Live Ajax Search plugin for WordPress is vulnerable to arbitrary post title disclosure in versions up to, and including, 1.6.1. This is due to insufficient checking of a post status before displaying to a user. This makes it possible for unauthenticated attackers to view post titles even when they are not in a 'publish' state.
Technical Analysis
REMEDIATION: Update to version 1.6.2, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C