plugin

Ajax Search Pro Vulnerabilities

13 known security issues reported for the Ajax Search Pro WordPress plugin. Most recent disclosed Apr 24, 2023.

2 high 2 medium

Running Ajax Search Pro on your site? Check whether your installed version is affected.

Scan your site free

Ajax Search Pro [ajax-search-pro] < 4.26.2

unknown

[en] The Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise and escape various parameters before outputting them back in pages, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Affected:
up to 4.26.2
Fixed in:
4.26.2
Disclosed:
Apr 24, 2023

CVE-2023-1435 on NVD →

Ajax Search Pro [ajax-search-pro] < 4.26.2

unknown

[en] The Ajax Search Lite WordPress plugin before 4.11.1, Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise and escape a parameter before outputting it back in a response of an AJAX action, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Affected:
up to 4.26.2
Fixed in:
4.26.2
Disclosed:
Apr 24, 2023

CVE-2023-1420 on NVD →

Ajax Search Pro <= 4.26.1 - Reflected Cross-Site Scripting

medium

The Ajax Search Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via some of its parameters in versions up to, and including, 4.26.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exe...

CVSS:
6.1
Affected:
up to 4.26.1
Fixed in:
4.26.2
Disclosed:
Apr 3, 2023

CVE-2023-1435 on NVD →

Ajax Search Pro <= 4.18.7 - Authenticated (Subscriber+) SQL Injection

high

The Ajax Search Pro plugin for WordPress is vulnerable to SQL Injection via the ‘p_blogid’ parameter in versions up to, and including, 4.18.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with...

CVSS:
8.8
Affected:
up to 4.18.7
Fixed in:
4.19
Disclosed:
Aug 3, 2020

Ajax Search Pro <= 4.18.7 - Cross-Site Request Forgery to Cross-Site Scripting

medium

The Ajax Search Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.18.7. This is due to missing or incorrect nonce validation in one of its functions. This makes it possible for unauthenticated attackers to invoke the vulnerable function via a forged request granted...

CVSS:
6.1
Affected:
up to 4.18.7
Fixed in:
4.19
Disclosed:
Aug 3, 2020

Ajax Search Pro [ajax-search-pro] < 4.19

unknown

The Ajax Search Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.18.7. This is due to missing or incorrect nonce validation in one of its functions. This makes it possible for unauthenticated attackers to invoke the vulnerable function via a forged request granted...

Affected:
up to 4.19
Fixed in:
4.19
Disclosed:
Aug 3, 2020

Ajax Search Pro [ajax-search-pro] < 4.19

unknown

The Ajax Search Pro plugin for WordPress is vulnerable to SQL Injection via the ‘p_blogid’ parameter in versions up to, and including, 4.18.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with...

Affected:
up to 4.19
Fixed in:
4.19
Disclosed:
Aug 3, 2020

Ajax Search Pro <= 3.5 - Cross-Site Request Forgery

high

The Ajax Search Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5. This is due to missing or incorrect nonce validation on the 'wpdreams_ajaxinputcallback' function. This makes it possible for unauthenticated attackers to execute any arbitrary function via a forg...

CVSS:
8.8
Affected:
up to 3.5
Fixed in:
4.0
Disclosed:
Mar 18, 2015

Ajax Search Pro [ajax-search-pro] < 1.1

unknown

Because of this vulnerability, any registered user to execute any function he wants with 1st param set to array($_POST). Update the plugin.

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Mar 18, 2015

Ajax Search Pro [ajax-search-pro] < 4.0

unknown

The Ajax Search Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5. This is due to missing or incorrect nonce validation on the 'wpdreams_ajaxinputcallback' function. This makes it possible for unauthenticated attackers to execute any arbitrary function via a forg...

Affected:
up to 4.0
Fixed in:
4.0
Disclosed:
Mar 18, 2015

Ajax Search Pro [ajax-search-pro] < 4.0

unknown

The ajax-search-pro WordPress plugin was affected by a Cross-Site Request Forgery (CSRF) Add User security vulnerability.

Affected:
up to 4.0
Fixed in:
4.0

Ajax Search Pro [ajax-search-pro] < 4.19

unknown

The plugin does not properly escape user input as it gets into an SQL query in certain AJAX actions.

Affected:
up to 4.19
Fixed in:
4.19

Ajax Search Pro [ajax-search-pro] < 4.19

unknown

The plugin does not properly sanitize and escape user input before printing it back into the administration panel.

Affected:
up to 4.19
Fixed in:
4.19

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database