What the vulnerability does
01Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ernest Marcinko Ajax Search Lite plugin <= 4.10.3 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ernest Marcinko Ajax Search Lite plugin <= 4.10.3 versions.
Explanation of Vulnerability in Simple Terms
Ajax Search Lite versions up to 4.10.3 expose sensitive information to authenticated users. A logged-in attacker can read data they should not have access to through the plugin's search functionality. The vulnerability requires a valid user account but no special privileges. Update to a version newer than 4.10.3 to resolve this issue.
What an attacker can do
Read sensitive information accessible through search queries that should be restricted.
Potential impact on your site
Authenticated users can access private or restricted content via search, risking data leakage.
Conditions required to exploit
Attacker must have a valid user account on the site (low-privilege login).
Key dates
External resources
Related vulnerabilities