Impact
This flaw allows an attacker to perform plugin actions without needing to authenticate, effectively bypassing any intended access restrictions. The vulnerability targets WP Fast Total Search plugin versions 1.81.282 and earlier. An attacker could potentially manipulate search index data, alter configuration settings, or execute other privileged operations, harming the confidentiality and integrity of the website's content and settings.
Affected Systems
The vulnerability affects the WP Fast Total Search plugin developed by Epsiloncool, used within WordPress installations. All releases up to and including version 1.81.282 are impacted; newer releases are presumed unaffected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% signals a low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Attackers can likely exploit the issue by sending requests to the plugin’s front‑end interfaces, requiring only network access to the WordPress site and no prior authentication.
OpenCVE Enrichment