CVE-2020-12070

HIGH

Advanced Woo Search < 1.99 - Sensitive Information Disclosure via AJAX Search SQL Field

Title source: llm
STIX 2.1

Description

The Advanced Woo Search plugin version through 1.99 for Wordpress suffers from a sensitive information disclosure vulnerability in every ajax search request via the sql field to includes/class-aws-search.php.

Scores

CVSS v3 7.5
EPSS 0.0198
EPSS Percentile 78.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (1)
advanced-woo-search/advanced_woo_search < 1.99
Published Apr 24, 2020
Tracked Since Feb 18, 2026