CVE-2022-40223
Published Nov 8, 2022Nonce token leakage and missing authorization in SearchWP premium plugin <= 4.2.5 on WordPress leading to plugin settings change.
Vendor archive
2 CVEs tagged to vendor searchwp — 0 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.
Nonce token leakage and missing authorization in SearchWP premium plugin <= 4.2.5 on WordPress leading to plugin settings change.
The SearchWP Live Ajax Search WordPress plugin before 1.6.2 does not ensure that users making a live search are limited to published posts only, allowing unauthenticated users to…