Path Traversal vulnerability in CodeManas Search with Typesense allows Path Traversal. This issue affects Search with Typesense: from n/a through 2.0.8.
Fixes

Solution

Update the WordPress Search with Typesense wordpress plugin to the latest available version (at least 2.0.9).


Workaround

No workaround given by the vendor.

History

Tue, 01 Jul 2025 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Codemanas
Codemanas search With Typesense
CPEs cpe:2.3:a:codemanas:search_with_typesense:*:*:*:*:*:wordpress:*:*
Vendors & Products Codemanas
Codemanas search With Typesense

Tue, 25 Feb 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Feb 2025 14:30:00 +0000

Type Values Removed Values Added
Description Path Traversal vulnerability in CodeManas Search with Typesense allows Path Traversal. This issue affects Search with Typesense: from n/a through 2.0.8.
Title WordPress Search with Typesense Plugin <= 2.0.8 - Path Traversal vulnerability
Weaknesses CWE-35
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2025-08-26T19:33:58.109Z

Reserved: 2025-02-17T11:49:35.314Z

Link: CVE-2025-26876

cve-icon Vulnrichment

Updated: 2025-02-25T14:39:41.994Z

cve-icon NVD

Status : Modified

Published: 2025-02-25T15:15:24.180

Modified: 2025-08-26T20:15:38.400

Link: CVE-2025-26876

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.