Description
Unauthenticated Broken Access Control in WP Fast Total Search <= 1.82.284 versions.
Published: 2026-09-10
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access via Broken Access Control
Action: Immediate Patch
AI Analysis

Impact

An unauthenticated attacker can exploit a missing permission check in the WP Fast Total Search plugin. The flaw allows the user to access plugin functionality without authentication, potentially revealing internal data or performing undesired actions. the primary weakness is identified as a Broken Access Control flaw.

Affected Systems

Vendors affected include Epsiloncool’s WP Fast Total Search WordPress plugin. Versions up to and including 1.82.284 are vulnerable, requiring update to at least version 1.83.286 to address the issue.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity vulnerability, with no EPSS score available and the vulnerability not listed in CISA KEV. Based on the description, the attack vector is remote via HTTP requests to the plugin’s endpoints, and unauthenticated users can exploit the flaw. The risk level is significant, and because the flaw is straightforward to exploit, it should be considered a high-priority patch.

Generated by OpenCVE AI on September 10, 2026 at 15:37 UTC.

Remediation

Vendor Solution

Update the WordPress WP Fast Total Search Plugin to the latest available version (at least 1.83.286).


OpenCVE Recommended Actions

  • Apply the latest WP Fast Total Search plugin version (at least 1.83.286).
  • If an immediate upgrade is not possible, restrict unauthenticated access to the plugin’s URLs or disable the plugin until the update is applied.
  • Monitor web server logs for unauthorized access attempts to the plugin’s endpoints to detect potential exploitation.

Generated by OpenCVE AI on September 10, 2026 at 15:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Epsiloncool
Epsiloncool wp Fast Total Search
Wordpress
Wordpress wordpress
Vendors & Products Epsiloncool
Epsiloncool wp Fast Total Search
Wordpress
Wordpress wordpress

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in WP Fast Total Search <= 1.82.284 versions.
Title WordPress WP Fast Total Search plugin <= 1.82.284 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Epsiloncool Wp Fast Total Search
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-10T14:53:15.486Z

Reserved: 2026-09-02T10:29:50.812Z

Link: CVE-2026-84821

cve-icon Vulnrichment

Updated: 2026-09-10T14:53:11.562Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T15:17:49.123

Modified: 2026-09-10T15:43:28.913

Link: CVE-2026-84821

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T10:45:06Z

Weaknesses