WP Fast Total Search <= 1.80.280 - Unauthenticated SQL Injection
high
The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to generic SQL Injection via the 'form_data[s]' parameter in all versions up to, and including, 1.80.280 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. Thi...
- CVSS:
- 7.5
- Affected:
- up to 1.80.280
- Fix:
- No patched version reported
- Disclosed:
- Jul 27, 2026
CVE-2026-12741 on NVD →
WP Fast Total Search – The Power of Indexed Search <= 1.81.282 - Missing Authorization
medium
The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.81.282. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.81.282
- Fixed in:
- 1.81.284
- Disclosed:
- Jul 22, 2026
CVE-2026-27418 on NVD →
WP Fast Total Search – The Power of Indexed Search <= 1.80.280 - Unauthenticated SQL Injection
high
The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.80.280 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attac...
- CVSS:
- 7.5
- Affected:
- up to 1.80.280
- Fixed in:
- 1.81.282
- Disclosed:
- Jun 29, 2026
CVE-2026-57683 on NVD →
WP Fast Total Search <= 1.79.270 - Cross-Site Request Forgery
medium
The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.79.270. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized acti...
- CVSS:
- 4.3
- Affected:
- up to 1.79.270
- Fixed in:
- 1.79.274
- Disclosed:
- Aug 22, 2025
CVE-2025-57893 on NVD →
WP Fast Total Search – The Power of Indexed Search [fulltext-search] < 1.79.274 (closed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Epsiloncool WP Fast Total Search allows Cross Site Request Forgery. This issue affects WP Fast Total Search: from n/a through 1.79.270.
- Affected:
- up to 1.79.274
- Fixed in:
- 1.79.274
- Disclosed:
- Aug 22, 2025
CVE-2025-57893 on NVD →
WP Fast Total Search <= 1.79.262 - Missing Authorization
medium
The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.79.262. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unaut...
- CVSS:
- 4.3
- Affected:
- up to 1.79.262
- Fixed in:
- 1.79.264
- Disclosed:
- Mar 27, 2025
CVE-2025-30894 on NVD →
WP Fast Total Search – The Power of Indexed Search [fulltext-search] < 1.79.264 (closed)
unknown
[en] Missing Authorization vulnerability in Epsiloncool WP Fast Total Search allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Fast Total Search: from n/a through 1.79.262.
- Affected:
- up to 1.79.264
- Fixed in:
- 1.79.264
- Disclosed:
- Mar 27, 2025
CVE-2025-30894 on NVD →
WP Fast Total Search <= 1.78.258 - Missing Authorization
medium
The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.78.258. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unaut...
- CVSS:
- 4.3
- Affected:
- up to 1.78.258
- Fixed in:
- 1.79.262
- Disclosed:
- Jan 24, 2025
CVE-2025-24571 on NVD →
WP Fast Total Search <= 1.78.258 - Cross-Site Request Forgery
medium
The WP Fast Total Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.78.258. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted th...
- CVSS:
- 4.3
- Affected:
- up to 1.78.258
- Fixed in:
- 1.79.262
- Disclosed:
- Jan 24, 2025
CVE-2025-24572 on NVD →
WP Fast Total Search – The Power of Indexed Search [fulltext-search] < 1.79.262 (closed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Epsiloncool WP Fast Total Search allows Cross Site Request Forgery. This issue affects WP Fast Total Search: from n/a through 1.78.258.
- Affected:
- up to 1.79.262
- Fixed in:
- 1.79.262
- Disclosed:
- Jan 24, 2025
CVE-2025-24572 on NVD →
WP Fast Total Search – The Power of Indexed Search [fulltext-search] < 1.79.262 (closed)
unknown
[en] Missing Authorization vulnerability in Epsiloncool WP Fast Total Search allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Fast Total Search: from n/a through 1.78.258.
- Affected:
- up to 1.79.262
- Fixed in:
- 1.79.262
- Disclosed:
- Jan 24, 2025
CVE-2025-24571 on NVD →
WP Fast Total Search – The Power of Indexed Search [fulltext-search] < 1.70.236 (closed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Epsiloncool WP Fast Total Search.This issue affects WP Fast Total Search: from n/a through 1.69.234.
- Affected:
- up to 1.70.236
- Fixed in:
- 1.70.236
- Disclosed:
- Jan 2, 2025
CVE-2024-38778 on NVD →
WP Fast Total Search – The Power of Indexed Search [fulltext-search] < 1.69.234 (closed)
unknown
[en] Missing Authorization vulnerability in Epsiloncool WP Fast Total Search allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Fast Total Search: from n/a through 1.68.232.
- Affected:
- up to 1.69.234
- Fixed in:
- 1.69.234
- Disclosed:
- Nov 1, 2024
CVE-2024-38714 on NVD →
WP Fast Total Search <= 1.68.232 - Unauthenticated Stored Cross-Site Scripting
high
The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.68.232 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...
- CVSS:
- 7.2
- Affected:
- up to 1.68.232
- Fixed in:
- 1.69.234
- Disclosed:
- Aug 1, 2024
CVE-2024-39663 on NVD →
WP Fast Total Search – The Power of Indexed Search [fulltext-search] < 1.69.234 (closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Epsiloncool WP Fast Total Search allows Stored XSS.This issue affects WP Fast Total Search: from n/a through 1.68.232.
- Affected:
- up to 1.69.234
- Fixed in:
- 1.69.234
- Disclosed:
- Aug 1, 2024
CVE-2024-39663 on NVD →
WP Fast Total Search <= 1.69.234 - Cross-Site Request Forgery
medium
The WP Fast Total Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.69.234. This is due to missing or incorrect nonce validation on the ajax_get_qlog_data and ajax_se_style_reset functions. This makes it possible for unauthenticated attackers to reset style data...
- CVSS:
- 4.3
- Affected:
- up to 1.69.234
- Fixed in:
- 1.70.236
- Disclosed:
- Jul 19, 2024
CVE-2024-38778 on NVD →
WP Fast Total Search <= 1.68.232 - Missing Authorization
medium
The WP Fast Total Search plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions like ajax_set_pause, ajax_se_style_preview, and WPFTS_jxResponse in versions up to, and including, 1.68.232. This makes it possible for authenticated attackers, with su...
- CVSS:
- 4.3
- Affected:
- up to 1.68.232
- Fixed in:
- 1.69.234
- Disclosed:
- Jul 11, 2024
CVE-2024-38714 on NVD →
WP Fast Total Search – The Power of Indexed Search [fulltext-search] < 1.60.213 (closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Epsiloncool WP Fast Total Search allows Stored XSS.This issue affects WP Fast Total Search: from n/a through 1.59.211.
- Affected:
- up to 1.60.213
- Fixed in:
- 1.60.213
- Disclosed:
- Mar 27, 2024
CVE-2024-29799 on NVD →
WP Fast Total Search <= 1.59.211 - Authenticated (Contributor+) Stored Cross-Site Scripting via WPFTS Live Search Widget
medium
The WP Fast Total Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the WPFTS Live Search widget in versions up to, and including, 1.59.211 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,...
- CVSS:
- 6.4
- Affected:
- up to 1.59.211
- Fixed in:
- 1.60.213
- Disclosed:
- Mar 25, 2024
CVE-2024-29799 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database