CVE-2012-5853
AJAX Post Search < 1.3 - SQL Injection via srch_txt Parameter
Title source: llmDescription
SQL injection vulnerability in the "the_search_function" function in cardoza_ajax_search.php in the AJAX Post Search (cardoza-ajax-search) plugin before 1.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the srch_txt parameter in a "the_search_text" action to wp-admin/admin-ajax.php.
References (2)
Core 2
Core References
Third Party Advisory x_refsource_confirm
https://wordpress.org/plugins/cardoza-ajax-search/changelog/
Exploit, Mailing List, Third Party Advisory mailing-list
x_refsource_bugtraq
http://seclists.org/bugtraq/2012/Nov/33
Scores
EPSS
0.0224
EPSS Percentile
81.0%
Details
CWE
CWE-89
Status
published
Products (1)
vinojcardoza/ajax_post_search
< 1.3
Published
Jan 08, 2015
Tracked Since
Feb 18, 2026