WPSOLR – Elasticsearch and Solr search [wpsolr-search-engine] < 8.7
unknown[en] Reflected XSS in wordpress plugin wpsolr-search-engine v7.6
- Affected:
- up to 8.7
- Fixed in:
- 8.7
- Disclosed:
- Oct 10, 2016
plugin
3 known security issues reported for the Wpsolr Search Engine WordPress plugin. Most recent disclosed Oct 10, 2016.
Running Wpsolr Search Engine on your site? Check whether your installed version is affected.
Scan your site free[en] Reflected XSS in wordpress plugin wpsolr-search-engine v7.6
The WPSOLR – Elasticsearch and Solr search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 8.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...
Because of this vulnerability, the attackers can inject arbitrary web script or HTML. Update the plugin.
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free