Missing Authorization Vulnerability Affects Advance WordPress Search Plugin
CVE-2022-40218

6.5MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
8 May 2024

Summary

The Advance WordPress Search Plugin developed by ThemeHunk is prone to a missing authorization vulnerability. This flaw allows unauthorized users to manipulate the plugin's settings, which may compromise the security and confidentiality of the affected WordPress instances. The vulnerability impacts all plugin versions up to and including 1.1.4, posing a risk to website administrators and users relying on this plugin for enhanced search functionalities. It is crucial for users to update to a patched version to safeguard against potential unauthorized access and ensure the integrity of their WordPress installations.

Affected Version(s)

Advance WordPress Search Plugin <= 1.1.4

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rasi Afeef (Patchstack Alliance)
.