What the vulnerability does
01Description
Missing Authorization vulnerability in ThemeHunk Advance WordPress Search Plugin.This issue affects Advance WordPress Search Plugin: from n/a through 1.1.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in ThemeHunk Advance WordPress Search Plugin.This issue affects Advance WordPress Search Plugin: from n/a through 1.1.4.
Explanation of Vulnerability in Simple Terms
The Advance WordPress Search plugin through version 1.1.4 lacks proper authorization checks on certain functionality. An unauthenticated attacker can modify data or disrupt site operations without needing to log in or interact with a user. Site administrators should update the plugin immediately to a version newer than 1.1.4.
What an attacker can do
Modify plugin data or disrupt site search functionality without authentication.
Potential impact on your site
Attackers can tamper with search settings or availability without your knowledge or permission.
Conditions required to exploit
Network access to the WordPress site; no login or user interaction required.
Key dates
External resources
Related vulnerabilities