plugin

Wpsolr Search Engine Vulnerabilities

3 known security issues reported for the Wpsolr Search Engine WordPress plugin. Most recent disclosed Oct 10, 2016.

1 medium

Running Wpsolr Search Engine on your site? Check whether your installed version is affected.

Scan your site free

WPSOLR – Elasticsearch and Solr search [wpsolr-search-engine] < 8.7

unknown

[en] Reflected XSS in wordpress plugin wpsolr-search-engine v7.6

Affected:
up to 8.7
Fixed in:
8.7
Disclosed:
Oct 10, 2016

CVE-2016-1000155 on NVD →

WPSOLR – Elasticsearch and Solr search <= 8.6 - Reflected Cross-Site Scripting

medium

The WPSOLR – Elasticsearch and Solr search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 8.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...

CVSS:
6.1
Affected:
up to 8.6
Fixed in:
8.7
Disclosed:
Apr 12, 2016

CVE-2016-1000155 on NVD →

WPSOLR – Elasticsearch and Solr search [wpsolr-search-engine] < 8.7 (closed)

unknown

Because of this vulnerability, the attackers can inject arbitrary web script or HTML. Update the plugin.

Affected:
up to 8.7
Fixed in:
8.7
Disclosed:
Apr 12, 2016

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database