Ajax Search Pro [ajax-search-pro] < 4.26.2
unknown
[en] The Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise and escape various parameters before outputting them back in pages, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
- Affected:
- up to 4.26.2
- Fixed in:
- 4.26.2
- Disclosed:
- Apr 24, 2023
CVE-2023-1435 on NVD →
Ajax Search Pro [ajax-search-pro] < 4.26.2
unknown
[en] The Ajax Search Lite WordPress plugin before 4.11.1, Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise and escape a parameter before outputting it back in a response of an AJAX action, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
- Affected:
- up to 4.26.2
- Fixed in:
- 4.26.2
- Disclosed:
- Apr 24, 2023
CVE-2023-1420 on NVD →
Ajax Search Pro <= 4.26.1 - Reflected Cross-Site Scripting
medium
The Ajax Search Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via some of its parameters in versions up to, and including, 4.26.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exe...
- CVSS:
- 6.1
- Affected:
- up to 4.26.1
- Fixed in:
- 4.26.2
- Disclosed:
- Apr 3, 2023
CVE-2023-1435 on NVD →
Ajax Search Pro <= 4.18.7 - Authenticated (Subscriber+) SQL Injection
high
The Ajax Search Pro plugin for WordPress is vulnerable to SQL Injection via the ‘p_blogid’ parameter in versions up to, and including, 4.18.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with...
- CVSS:
- 8.8
- Affected:
- up to 4.18.7
- Fixed in:
- 4.19
- Disclosed:
- Aug 3, 2020
Ajax Search Pro <= 4.18.7 - Cross-Site Request Forgery to Cross-Site Scripting
medium
The Ajax Search Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.18.7. This is due to missing or incorrect nonce validation in one of its functions. This makes it possible for unauthenticated attackers to invoke the vulnerable function via a forged request granted...
- CVSS:
- 6.1
- Affected:
- up to 4.18.7
- Fixed in:
- 4.19
- Disclosed:
- Aug 3, 2020
Ajax Search Pro [ajax-search-pro] < 4.19
unknown
The Ajax Search Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.18.7. This is due to missing or incorrect nonce validation in one of its functions. This makes it possible for unauthenticated attackers to invoke the vulnerable function via a forged request granted...
- Affected:
- up to 4.19
- Fixed in:
- 4.19
- Disclosed:
- Aug 3, 2020
Ajax Search Pro [ajax-search-pro] < 4.19
unknown
The Ajax Search Pro plugin for WordPress is vulnerable to SQL Injection via the ‘p_blogid’ parameter in versions up to, and including, 4.18.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with...
- Affected:
- up to 4.19
- Fixed in:
- 4.19
- Disclosed:
- Aug 3, 2020
Ajax Search Pro <= 3.5 - Cross-Site Request Forgery
high
The Ajax Search Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5. This is due to missing or incorrect nonce validation on the 'wpdreams_ajaxinputcallback' function. This makes it possible for unauthenticated attackers to execute any arbitrary function via a forg...
- CVSS:
- 8.8
- Affected:
- up to 3.5
- Fixed in:
- 4.0
- Disclosed:
- Mar 18, 2015
Ajax Search Pro [ajax-search-pro] < 1.1
unknown
Because of this vulnerability, any registered user to execute any function he wants with
1st param set to array($_POST).
Update the plugin.
- Affected:
- up to 1.1
- Fixed in:
- 1.1
- Disclosed:
- Mar 18, 2015
Ajax Search Pro [ajax-search-pro] < 4.0
unknown
The Ajax Search Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5. This is due to missing or incorrect nonce validation on the 'wpdreams_ajaxinputcallback' function. This makes it possible for unauthenticated attackers to execute any arbitrary function via a forg...
- Affected:
- up to 4.0
- Fixed in:
- 4.0
- Disclosed:
- Mar 18, 2015
Ajax Search Pro [ajax-search-pro] < 4.0
unknown
The ajax-search-pro WordPress plugin was affected by a Cross-Site Request Forgery (CSRF) Add User security vulnerability.
- Affected:
- up to 4.0
- Fixed in:
- 4.0
Ajax Search Pro [ajax-search-pro] < 4.19
unknown
The plugin does not properly escape user input as it gets into an SQL query in certain AJAX actions.
- Affected:
- up to 4.19
- Fixed in:
- 4.19
Ajax Search Pro [ajax-search-pro] < 4.19
unknown
The plugin does not properly sanitize and escape user input before printing it back into the administration panel.
- Affected:
- up to 4.19
- Fixed in:
- 4.19
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database