plugin

Searchpro Vulnerabilities

10 known security issues reported for the Searchpro WordPress plugin. Most recent disclosed Sep 9, 2025.

1 critical 2 high 2 medium

Running Searchpro on your site? Check whether your installed version is affected.

Scan your site free

BerqWP <= 2.2.53 - Missing Authorization

medium

The BerqWP – Automated All-In-One Page Speed Optimization for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.2.53. This makes it possible for unauthenticated attack...

CVSS:
5.3
Affected:
up to 2.2.53
Fixed in:
2.2.54
Disclosed:
Sep 9, 2025

CVE-2025-58979 on NVD →

BerqWP &#8211; Automated All-In-One Page Speed Optimization for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript [searchpro] < 2.2.54

unknown

[en] Missing Authorization vulnerability in BerqWP BerqWP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects BerqWP: from n/a through 2.2.53.

Affected:
up to 2.2.54
Fixed in:
2.2.54
Disclosed:
Sep 9, 2025

CVE-2025-58979 on NVD →

BerqWP <= 2.2.42 - Unauthenticated Arbitrary File Upload

high

The BerqWP – Automated All-In-One Page Speed Optimization for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the store_javascript_cache.php file in all versions up to, and including, 2.2.42. This makes it poss...

CVSS:
8.1
Affected:
up to 2.2.42
Fixed in:
2.2.44
Disclosed:
Jul 31, 2025

CVE-2025-7443 on NVD →

BerqWP &#8211; Automated All-In-One Page Speed Optimization for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript [searchpro] < 2.1.2 (closed)

unknown

[en] The BerqWP – Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' parameter in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output esc...

Affected:
up to 2.1.2
Fixed in:
2.1.2
Disclosed:
Oct 2, 2024

CVE-2024-9344 on NVD →

BerqWP – Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript <= 2.1.1 - Reflected Cross-Site Scripting

medium

The BerqWP – Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' parameter in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping...

CVSS:
6.1
Affected:
up to 2.1.1
Fixed in:
2.1.2
Disclosed:
Oct 1, 2024

CVE-2024-9344 on NVD →

BerqWP &#8211; Automated All-In-One Page Speed Optimization for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript [searchpro] < 1.7.7 (closed)

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in BerqWP allows Code Injection.This issue affects BerqWP: from n/a through 1.7.6.

Affected:
up to 1.7.7
Fixed in:
1.7.7
Disclosed:
Aug 13, 2024

CVE-2024-43160 on NVD →

BerqWP <= 1.7.6 - Unauthenticated Arbitrary File Uplaod

critical

The BerqWP – Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the /api/store_webp.php file in all versions up to, and including, 1.7.6. This makes it possibl...

CVSS:
9.8
Affected:
up to 1.7.6
Fixed in:
1.7.7
Disclosed:
Aug 7, 2024

CVE-2024-43160 on NVD →

BerqWP &#8211; Automated All-In-One Page Speed Optimization for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript [searchpro] < 1.7.6 (closed)

unknown

[en] Server-Side Request Forgery (SSRF) vulnerability in Berqier Ltd BerqWP.This issue affects BerqWP: from n/a through 1.7.5.

Affected:
up to 1.7.6
Fixed in:
1.7.6
Disclosed:
Jul 22, 2024

CVE-2024-37942 on NVD →

BerqWP <= 1.7.5 - Unauthenticated Server-Side Request Forgery

high

The BerqWP – Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.7.5. This makes it possible for unauthenticated attackers to make web requests to arbitra...

CVSS:
7.2
Affected:
up to 1.7.5
Fixed in:
1.7.6
Disclosed:
Jul 10, 2024

CVE-2024-37942 on NVD →

BerqWP &#8211; Automated All-In-One Page Speed Optimization for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript [searchpro] < 2.2.44 (closed)

unknown
Affected:
up to 2.2.44
Fixed in:
2.2.44

CVE-2025-7443 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database