CVE-2012-5853

AJAX Post Search < 1.3 - SQL Injection via srch_txt Parameter

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in the "the_search_function" function in cardoza_ajax_search.php in the AJAX Post Search (cardoza-ajax-search) plugin before 1.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the srch_txt parameter in a "the_search_text" action to wp-admin/admin-ajax.php.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_confirm
https://wordpress.org/plugins/cardoza-ajax-search/changelog/
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_bugtraq
http://seclists.org/bugtraq/2012/Nov/33

Scores

EPSS 0.0224
EPSS Percentile 81.0%

Details

CWE
CWE-89
Status published
Products (1)
vinojcardoza/ajax_post_search < 1.3
Published Jan 08, 2015
Tracked Since Feb 18, 2026