Predictive Search <= 1.2.2 - Missing Authorization
medium
The Predictive Search plugin for WordPress is vulnerable to unauthorized modification and disclosure of data due to missing capability checks on the wp_predictive_search_start_sync_ajax, wp_predictive_search_sync_taxonomy_ajax, wp_predictive_search_sync_relationships_ajax, wp_predictive_search_sync_posts_ajax, wp_pred...
- CVSS:
- 6.5
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.3
- Disclosed:
- May 15, 2023
Predictive Search <= 1.2.2 - Missing Authorization
medium
The Predictive Search plugin for WordPress is vulnerable to unauthorized disclosure of data due to a missing capability check on the 'get_exclude_options_ajax' function called via a wp_ajax and wp_ajax_nopriv hook in versions up to, and including, 1.2.2. This makes it possible for unauthenticated attackers to retrieve...
- CVSS:
- 6.5
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.3
- Disclosed:
- May 15, 2023
Predictive Search <= 1.2.2 - Missing Authorization
medium
The Predictive Search plugin for WordPress is vulnerable to unauthorized modification and disclosure of data due to missing capability checks on the wp_predictive_search_rebuild_cat_cache_ajax and wp_predictive_search_build_category_cache_error_ajax functions called via wp_ajax and wp_ajax_nopriv hooks in versions up t...
- CVSS:
- 6.5
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.3
- Disclosed:
- May 15, 2023
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database