The Ajax Search Lite WordPress plugin before 4.12.1 does not sanitise and escape some parameters, which could allow users with a role as low as Admin+ to perform Cross-Site Scripting attacks.

Subscriptions

Vendors Products
Ajax Search Project Subscribe
Ajax Search Subscribe
Wp-dreams Subscribe
Ajax Search Subscribe

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 28 May 2025 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Wp-dreams
Wp-dreams ajax Search
Weaknesses CWE-79
CPEs cpe:2.3:a:wp-dreams:ajax_search:*:*:*:*:lite:wordpress:*:*
Vendors & Products Wp-dreams
Wp-dreams ajax Search

Fri, 01 Nov 2024 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Ajax Search Project
Ajax Search Project ajax Search
CPEs cpe:2.3:a:ajax_search_project:ajax_search:*:*:*:*:lite:wordpress:*:*
Vendors & Products Ajax Search Project
Ajax Search Project ajax Search
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2024-11-01T20:44:09.200Z

Reserved: 2024-07-24T16:58:07.625Z

Link: CVE-2024-7084

cve-icon Vulnrichment

Updated: 2024-08-06T14:20:24.924Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-06T06:15:36.480

Modified: 2025-05-28T19:41:14.140

Link: CVE-2024-7084

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses