What the vulnerability does
01Description
Missing Authorization vulnerability in ThemeHunk Advance WordPress Search Plugin.This issue affects Advance WordPress Search Plugin: from n/a through 1.2.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in ThemeHunk Advance WordPress Search Plugin.This issue affects Advance WordPress Search Plugin: from n/a through 1.2.1.
Explanation of Vulnerability in Simple Terms
The Advance WordPress Search plugin through version 1.2.1 lacks proper authorization checks on certain functions. An unauthenticated attacker can modify site data or cause the site to malfunction without needing to log in or interact with a user. Update the plugin immediately to a version newer than 1.2.1.
What an attacker can do
Modify site data or disrupt site functionality without authentication.
Potential impact on your site
Attackers can alter plugin settings, content, or cause service disruption without your knowledge or permission.
Conditions required to exploit
Network access to the WordPress site; no login or user interaction required.
Key dates
External resources
Related vulnerabilities