What the vulnerability does
01Description
Missing Authorization vulnerability in Epsiloncool WP Fast Total Search fulltext-search.This issue affects WP Fast Total Search: from n/a through <= 1.68.232.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in Epsiloncool WP Fast Total Search fulltext-search.This issue affects WP Fast Total Search: from n/a through <= 1.68.232.
Explanation of Vulnerability in Simple Terms
WP Fast Total Search contains an authorization flaw that allows authenticated users to access search functionality they should not have permission to use. An attacker with a low-privilege account can read sensitive search data without proper access controls. The vulnerability affects all versions up to 1.68.232. Update to a version newer than the affected range.
What an attacker can do
Read search data and results they should not have access to.
Potential impact on your site
Unauthorized users can view sensitive search information and indexed content they lack permission to access.
Conditions required to exploit
Attacker must have a low-privilege WordPress user account on the site.
Key dates
External resources
Related vulnerabilities