plugin

Elasticpress Vulnerabilities

20 known security issues reported for the Elasticpress WordPress plugin. Most recent disclosed Jun 8, 2024.

1 critical 2 high 3 medium 3 low

Running Elasticpress on your site? Check whether your installed version is affected.

Scan your site free

ElasticPress [elasticpress] < 5.1.1

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in 10up ElasticPress.This issue affects ElasticPress: from n/a through 5.1.1.

Affected:
up to 5.1.1
Fixed in:
5.1.1
Disclosed:
Jun 8, 2024

CVE-2024-35684 on NVD →

ElasticPress <= 5.1.0 - Cross-Site Request Forgery

medium

The ElasticPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1.0. This is due to missing or incorrect nonce validation on the do_sync function. This makes it possible for unauthenticated attackers to sync data via a forged request granted they can trick a sit...

CVSS:
4.3
Affected:
up to 5.1.0
Fixed in:
5.1.1
Disclosed:
Jun 6, 2024

CVE-2024-35684 on NVD →

ElasticPress [elasticpress] < 3.5.4

unknown

[en] The ElasticPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.3. This is due to missing or incorrect nonce validation on the epio_send_autosuggest_allowed() function. This makes it possible for unauthenticated attackers to send allowed parameters for autosu...

Affected:
up to 3.5.4
Fixed in:
3.5.4
Disclosed:
Jul 1, 2023

CVE-2021-4405 on NVD →

ElasticPress [elasticpress] < 3.5.4

unknown
Affected:
up to 3.5.4
Fixed in:
3.5.4
Disclosed:
Jun 7, 2023

CVE-2021-4342 on NVD →

webpack JS package <= 5.75.0 - Sandbox Bypass

high

The JS package webpack is vulnerable to Sandbox Bypass in versions up to, and including, 5.75.0 due to mishandling magic comments. Some WordPress plugins and themes use this dependency, however, are not vulnerable to exploitation.

CVSS:
8.3
Affected:
up to 4.5.0
Fixed in:
4.5.1
Disclosed:
Apr 11, 2023

CVE-2023-28154 on NVD →

ElasticPress [elasticpress] < 4.5.1

unknown

[en] Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.

Affected:
up to 4.5.1
Fixed in:
4.5.1
Disclosed:
Mar 13, 2023

CVE-2023-28154 on NVD →

simple-git < 3.15.0 - Remote Code Execution

critical

The package simple-git is vulnerable to Remote Code Execution in versions before 3.15.0 when the ext transport protocol is enabled. This makes the vulnerability exploitable using the clone method. WordPress plugins and themes may be using this package, however, may not be vulnerable to exploitation.

CVSS:
9.8
Affected:
up to 4.4.0
Fixed in:
4.4.1
Disclosed:
Dec 5, 2022

CVE-2022-25912 on NVD →

ElasticPress [elasticpress] < 4.4.0

unknown

[en] A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the url variable in interpolateName.js.

Affected:
up to 4.4.0
Fixed in:
4.4.0
Disclosed:
Oct 14, 2022

CVE-2022-37603 on NVD →

loader-utils (JS package) < 2.0.3 - Prototype Pollution

medium

The package loader-utils before 1.4.1, from 2.0.0 and before 2.0.3 is vulnerable to prototype pollution via the function parseQuery which could make injecting malicious web scripts possible in some cases.

CVSS:
5.4
Affected:
up to 4.3.1
Fixed in:
4.4.0
Disclosed:
Oct 12, 2022

CVE-2022-37601 on NVD →

ElasticPress [elasticpress] < 4.4.0

unknown

[en] Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.

Affected:
up to 4.4.0
Fixed in:
4.4.0
Disclosed:
Oct 12, 2022

CVE-2022-37601 on NVD →

loader-utils (JS package) < 3.2.1 - Regular Expression Denial of Service

low

The package loader-utils before 1.4.2, from 2.0.0 and before 2.0.4 as well as versions from 3.0.0 but below 3.2.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the interpolateName function due to insecure usage of regular expressions. Some WordPress plugins and themes use this dependency, however,...

CVSS:
3.7
Affected:
up to 4.3.1
Fixed in:
4.4.0
Disclosed:
Oct 11, 2022

CVE-2022-37599 on NVD →

loader-utils (JS package) < 3.2.1 - Regular Expression Denial of Service

low

The package loader-utils before 1.4.2, from 2.0.0 and before 2.0.4 as well as versions from 3.0.0 but below 3.2.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the resourcePath variable due to insecure usage of regular expressions. Some WordPress plugins and themes use this dependency, however, are...

CVSS:
3.7
Affected:
up to 4.3.1
Fixed in:
4.4.0
Disclosed:
Oct 11, 2022

CVE-2022-37603 on NVD →

ElasticPress [elasticpress] < 4.4.0

unknown

[en] A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the resourcePath variable in interpolateName.js.

Affected:
up to 4.4.0
Fixed in:
4.4.0
Disclosed:
Oct 11, 2022

CVE-2022-37599 on NVD →

ElasticPress [elasticpress] < 4.3.0

unknown

[en] The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions.

Affected:
up to 4.3.0
Fixed in:
4.3.0
Disclosed:
Jul 15, 2022

CVE-2022-25858 on NVD →

terser (JS Package) < 5.14.2 - Denial of Service

low

The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions. Some WordPress plugins and themes use this dependency, however, are not vulnerable to exploitation.

CVSS:
3.7
Affected:
up to 4.2.2
Fixed in:
4.3.0
Disclosed:
Jul 14, 2022

CVE-2022-25858 on NVD →

Moment.js <= 2.29.1 - Directory Traversal

high

The Javascript library moment.js is vulnerable to a path traversal vulnerability in versions up to, and including, 2.29.1. This makes it possible for attackers to read files outside of the accessed site's root directory leading to information disclosure.

CVSS:
7.5
Affected:
up to 4.1.0
Fixed in:
4.2.0
Disclosed:
Apr 5, 2022

ElasticPress [elasticpress] < 4.2.0

unknown

The Javascript library moment.js is vulnerable to a path traversal vulnerability in versions up to, and including, 2.29.1. This makes it possible for attackers to read files outside of the accessed site's root directory leading to information disclosure.

Affected:
up to 4.2.0
Fixed in:
4.2.0
Disclosed:
Apr 5, 2022

ElasticPress <= 3.5.3 - Cross-Site Request Forgery Bypass

medium

The ElasticPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.3. This is due to missing or incorrect nonce validation on the epio_send_autosuggest_allowed() function. This makes it possible for unauthenticated attackers to send allowed parameters for autosuggest...

CVSS:
4.3
Affected:
up to 3.5.3
Fixed in:
3.5.4
Disclosed:
Mar 1, 2021

CVE-2021-4405 on NVD →

ElasticPress [elasticpress] < 3.5.4

unknown

Nonce Check Bypass vulnerability found by Felipe Elia in WordPress ElasticPress plugin (versions <= 3.5.3).

Affected:
up to 3.5.4
Fixed in:
3.5.4
Disclosed:
Feb 12, 2021

ElasticPress [elasticpress] < 3.5.4

unknown

Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.

Affected:
up to 3.5.4
Fixed in:
3.5.4

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database