Record summary

CVE-2022-2535 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

The SearchWP Live Ajax Search WordPress plugin before 1.6.2 does not ensure that users making a live search are limited to published posts only, allowing unauthenticated users to make a crafted query disclosing private/draft/pending post titles along with their permalink

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

SearchWP Live Ajax Search

CVE List1.6.2 to < 1.6.2affected

Nuclei templates

1
ProjectDiscoveryMEDIUMSearchWP Live Ajax Search < 1.6.2 - Unauthenticated Arbitrary Post Title DisclosureCVSS 5.3

The plugin does not ensure that users making. alive search are limited to published posts only, allowing unauthenticated users to make a crafted query disclosing private/draft/pending post titles along with their permalink

Impact

Unauthenticated attackers can access titles and permalinks of private, draft, and pending posts through crafted live search queries with manipulated post_status parameters, potentially exposing confidential content before publication.

Remediation

Fixed in version 1.6.2

WeaknessesCWE-639
Authorsr3Y3r53, daffainfo
Template tagscvecve2022wpwp-pluginwordpresswpscansearchwp-live-ajax-searchsearchwpvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:searchwp:searchwp_live_ajax_search:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/searchwp-live-ajax-search/
FOFA: body=/wp-content/plugins/searchwp-live-ajax-search/

Source: ProjectDiscovery

References

2