SearchIQ <= 4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The SearchIQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will...
- CVSS:
- 6.4
- Affected:
- up to 4.7
- Fixed in:
- 4.8
- Disclosed:
- Mar 27, 2025
CVE-2025-30867 on NVD →
SearchIQ – The Search Solution [searchiq] < 4.8
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SearchIQ SearchIQ allows Stored XSS. This issue affects SearchIQ: from n/a through 4.7.
- Affected:
- up to 4.8
- Fixed in:
- 4.8
- Disclosed:
- Mar 27, 2025
CVE-2025-30867 on NVD →
SearchIQ – The Search Solution [searchiq] < 4.8
unknown
[en] The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siq_searchbox' shortcode in all versions up to, and including, 4.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...
- Affected:
- up to 4.8
- Fixed in:
- 4.8
- Disclosed:
- Mar 5, 2025
CVE-2024-13350 on NVD →
SearchIQ – The Search Solution <= 4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siq_searchbox' shortcode in all versions up to, and including, 4.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attac...
- CVSS:
- 6.4
- Affected:
- up to 4.7
- Fixed in:
- 4.8
- Disclosed:
- Mar 4, 2025
CVE-2024-13350 on NVD →
SearchIQ – The Search Solution [searchiq] < 4.7
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Searchiq SearchIQ.This issue affects SearchIQ: from n/a through 4.6.
- Affected:
- up to 4.7
- Fixed in:
- 4.7
- Disclosed:
- Dec 31, 2024
CVE-2024-56229 on NVD →
SearchIQ <= 4.6 - Cross-Site Request Forgery
medium
The SearchIQ plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.6. This is due to missing or incorrect nonce validation in the error-log.php file. This makes it possible for unauthenticated attackers to delete log records via a forged request granted they can trick a si...
- CVSS:
- 4.3
- Affected:
- up to 4.6
- Fixed in:
- 4.7
- Disclosed:
- Dec 19, 2024
CVE-2024-56229 on NVD →
SearchIQ – The Search Solution [searchiq] < 4.5
unknown
[en] Missing Authorization vulnerability in searchiq SearchIQ allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SearchIQ: from n/a through 4.4.
- Affected:
- up to 4.5
- Fixed in:
- 4.5
- Disclosed:
- Dec 9, 2024
CVE-2023-47832 on NVD →
SearchIQ – The Search Solution [searchiq] < 4.7
unknown
[en] The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siq_searchbox' shortcode in all versions up to, and including, 4.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...
- Affected:
- up to 4.7
- Fixed in:
- 4.7
- Disclosed:
- Dec 4, 2024
CVE-2024-10885 on NVD →
SearchIQ – The Search Solution <= 4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siq_searchbox' shortcode in all versions up to, and including, 4.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attac...
- CVSS:
- 6.4
- Affected:
- up to 4.6
- Fixed in:
- 4.7
- Disclosed:
- Dec 3, 2024
CVE-2024-10885 on NVD →
SearchIQ – The Search Solution [searchiq] < 4.6
unknown
[en] Insertion of Sensitive Information into Log File vulnerability in Searchiq SearchIQ.This issue affects SearchIQ: from n/a through 4.5.
- Affected:
- up to 4.6
- Fixed in:
- 4.6
- Disclosed:
- Apr 10, 2024
CVE-2024-31259 on NVD →
SearchIQ <= 4.5 - Unauthenticated Sensitive Information Exposure
medium
The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5 via log files. This makes it possible for unauthenticated attackers to extract sensitive data from log files.
- CVSS:
- 5.3
- Affected:
- up to 4.5
- Fixed in:
- 4.6
- Disclosed:
- Apr 5, 2024
CVE-2024-31259 on NVD →
SearchIQ <= 4.4 - Missing Authorization via getSIQPluginSettings
medium
The SearchIQ plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the getSIQPluginSettings function in versions up to, and including, 4.4. This makes it possible for unauthenticated attackers to view information such as the plugin settings, theme, and WordPress and PHP...
- CVSS:
- 5.3
- Affected:
- up to 4.4
- Fixed in:
- 4.5
- Disclosed:
- Nov 16, 2023
CVE-2023-47832 on NVD →
SearchIQ – The Search Solution [searchiq] < 3.9
unknown
[en] The SearchIQ WordPress plugin before 3.9 contains a flag to disable the verification of CSRF nonces, granting unauthenticated attackers access to the siq_ajax AJAX action and allowing them to perform Cross-Site Scripting attacks due to the lack of sanitisation and escaping in the customCss parameter
- Affected:
- up to 3.9
- Fixed in:
- 3.9
- Disclosed:
- Apr 18, 2022
CVE-2022-0780 on NVD →
SearchIQ – The Search Solution <= 3.8 - Unauthenticated Stored Cross-Site Scripting
high
The SearchIQ WordPress plugin before 3.9 contains a flag to disable the verification of CSRF nonces, granting unauthenticated attackers access to the siq_ajax AJAX action and allowing them to perform Cross-Site Scripting attacks due to the lack of sanitisation and escaping in the customCss parameter
- CVSS:
- 7.2
- Affected:
- up to 3.8
- Fixed in:
- 3.9
- Disclosed:
- Apr 11, 2022
CVE-2022-0780 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database