5.3
CVSSv3

CVE-2022-2535

Published: 15/08/2022 Updated: 16/08/2022
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The SearchWP Live Ajax Search WordPress plugin prior to 1.6.2 does not ensure that users making a live search are limited to published posts only, allowing unauthenticated users to make a crafted query disclosing private/draft/pending post titles along with their permalink

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

searchwp searchwp live ajax search