Impact
An unauthenticated attacker can exploit a missing permission check in the WP Fast Total Search plugin. The flaw allows the user to access plugin functionality without authentication, potentially revealing internal data or performing undesired actions. the primary weakness is identified as a Broken Access Control flaw.
Affected Systems
Vendors affected include Epsiloncool’s WP Fast Total Search WordPress plugin. Versions up to and including 1.82.284 are vulnerable, requiring update to at least version 1.83.286 to address the issue.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity vulnerability, with no EPSS score available and the vulnerability not listed in CISA KEV. Based on the description, the attack vector is remote via HTTP requests to the plugin’s endpoints, and unauthenticated users can exploit the flaw. The risk level is significant, and because the flaw is straightforward to exploit, it should be considered a high-priority patch.
OpenCVE Enrichment