Description
Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions.
Published: 2026-07-23
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This flaw allows an attacker to perform plugin actions without needing to authenticate, effectively bypassing any intended access restrictions. The vulnerability targets WP Fast Total Search plugin versions 1.81.282 and earlier. An attacker could potentially manipulate search index data, alter configuration settings, or execute other privileged operations, harming the confidentiality and integrity of the website's content and settings.

Affected Systems

The vulnerability affects the WP Fast Total Search plugin developed by Epsiloncool, used within WordPress installations. All releases up to and including version 1.81.282 are impacted; newer releases are presumed unaffected.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% signals a low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Attackers can likely exploit the issue by sending requests to the plugin’s front‑end interfaces, requiring only network access to the WordPress site and no prior authentication.

Generated by OpenCVE AI on August 3, 2026 at 22:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update WP Fast Total Search to the latest version
  • Restrict access to the plugin's administrative pages using web‑server authentication or .htaccess rules
  • Monitor access logs for abnormal activity or repeated attempts to use plugin endpoints

Generated by OpenCVE AI on August 3, 2026 at 22:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Epsiloncool
Epsiloncool wp Fast Total Search
Wordpress
Wordpress wordpress
Vendors & Products Epsiloncool
Epsiloncool wp Fast Total Search
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions.
Title WordPress WP Fast Total Search plugin <= 1.81.282 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Epsiloncool Wp Fast Total Search
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T16:02:24.492Z

Reserved: 2026-02-19T09:52:28.127Z

Link: CVE-2026-27418

cve-icon Vulnrichment

Updated: 2026-07-23T16:02:19.653Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:17:18.643

Modified: 2026-07-23T16:17:17.263

Link: CVE-2026-27418

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T22:45:04Z

Weaknesses