Impact
Based on the description, it is inferred that the WP Fast Total Search plugin for WordPress contains an unauthenticated SQL injection flaw (CWE‑89) that allows attackers to insert crafted search queries used directly in database statements without proper sanitization. This flaw permits arbitrary SQL execution, enabling the attacker to read, modify, or delete data in the WordPress database and potentially compromise the site’s content, configuration, and availability.
Affected Systems
Any WordPress site running Epsiloncool’s WP Fast Total Search plugin version 1.80.280 or earlier is affected. Sites that have not upgraded to version 1.81.282 or newer remain vulnerable.
Risk and Exploitability
The CVSS score of 9.3 classifies the vulnerability as critical. The EPSS score of <1% indicates a low but nonzero likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a public web request to the search interface, as authentication is not required, based on the description. If exploited, it is inferred leading to data loss, breach of confidentiality, or denial of service.
OpenCVE Enrichment