Advanced Woo Search <= 3.28 - Authenticated (Contributor+) Stored Cross-Site Scripting via aws_search_terms Shortcode
medium
The Advanced Woo Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aws_search_terms shortcode in all versions up to, and including, 3.28 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, wit...
- CVSS:
- 6.4
- Affected:
- up to 3.28
- Fixed in:
- 3.29
- Disclosed:
- Mar 25, 2025
CVE-2025-2302 on NVD →
Advanced Woo Search <= 2.96 - Reflected Cross-Site Scripting
medium
The Advanced Woo Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search parameter in all versions up to, and including, 2.96 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...
- CVSS:
- 6.1
- Affected:
- up to 2.96
- Fixed in:
- 2.97
- Disclosed:
- Jan 12, 2024
CVE-2024-0251 on NVD →
Advanced Woo Search <= 2.77 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Advanced Woo Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.77 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject a...
- CVSS:
- 4.4
- Affected:
- up to 2.77
- Fixed in:
- 2.78
- Disclosed:
- May 1, 2023
CVE-2023-2452 on NVD →
Advanced Woo Search <= 2.00 - Information Disclosure
medium
The Advanced Woo Search plugin version through 1.99 for Wordpress suffers from a sensitive information disclosure vulnerability in every ajax search request via the sql field to includes/class-aws-search.php.
- CVSS:
- 5.3
- Affected:
- up to 1.99
- Fixed in:
- 2.00
- Disclosed:
- Apr 23, 2020
CVE-2020-12070 on NVD →
Advanced Woo Search <= 1.68 - Cross-Site Scripting
high
The Advanced Woo Search plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.68 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 7.2
- Affected:
- up to 1.68
- Fixed in:
- 1.70
- Disclosed:
- May 2, 2019
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database