SearchWP Live Ajax Search <= 1.6.2 - Directory Traversal and Local File Inclusion
critical
The SearchWP Live Ajax Search plugin for WordPress is vulnerable to Directory Traversal via the 'swpengine' parameter used by the 'searchwp_live_search' AJAX action in versions up to, and including, 1.6.2. This allows unauthenticated attackers to include and execute arbitrary local PHP files.
- CVSS:
- 9.1
- Affected:
- 1.0 – 1.6.2
- Fixed in:
- 1.6.3
- Disclosed:
- Sep 15, 2022
CVE-2022-3227 on NVD →
SearchWP Live Ajax Search [searchwp-live-ajax-search] < 1.6.2
unknown
[en] The SearchWP Live Ajax Search WordPress plugin before 1.6.2 does not ensure that users making a live search are limited to published posts only, allowing unauthenticated users to make a crafted query disclosing private/draft/pending post titles along with their permalink
- Affected:
- up to 1.6.2
- Fixed in:
- 1.6.2
- Disclosed:
- Aug 15, 2022
CVE-2022-2535 on NVD →
SearchWP Live Ajax Search <= 1.6.1 - Sensitive Information Disclosure
medium
The SearchWP Live Ajax Search plugin for WordPress is vulnerable to arbitrary post title disclosure in versions up to, and including, 1.6.1. This is due to insufficient checking of a post status before displaying to a user. This makes it possible for unauthenticated attackers to view post titles even when they are not...
- CVSS:
- 5.3
- Affected:
- up to 1.6.1
- Fixed in:
- 1.6.2
- Disclosed:
- Jul 25, 2022
CVE-2022-2535 on NVD →
SearchWP Live Ajax Search [searchwp-live-ajax-search] < 1.6.3
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 1.6.3
- Fixed in:
- 1.6.3
CVE-2022-3227 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database