CVE-2022-2535
SearchWP Live Ajax Search < 1.6.2 - Unauthenticated Arbitrary Post Title Disclosure
Record summary
CVE-2022-2535 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
The SearchWP Live Ajax Search WordPress plugin before 1.6.2 does not ensure that users making a live search are limited to published posts only, allowing unauthenticated users to make a crafted query disclosing private/draft/pending post titles along with their permalink
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
SearchWP Live Ajax Search | CVE List | 1.6.2 to < 1.6.2 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMSearchWP Live Ajax Search < 1.6.2 - Unauthenticated Arbitrary Post Title DisclosureCVSS 5.3
The plugin does not ensure that users making. alive search are limited to published posts only, allowing unauthenticated users to make a crafted query disclosing private/draft/pending post titles along with their permalink
Impact
Unauthenticated attackers can access titles and permalinks of private, draft, and pending posts through crafted live search queries with manipulated post_status parameters, potentially exposing confidential content before publication.
Remediation
Fixed in version 1.6.2
Source: ProjectDiscovery