Description
Nonce token leakage and missing authorization in SearchWP premium plugin <= 4.2.5 on WordPress leading to plugin settings change.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update to 4.2.6 or higher version.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-43521 | Nonce token leakage and missing authorization in SearchWP premium plugin <= 4.2.5 on WordPress leading to plugin settings change. |
References
History
Thu, 20 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-04-28T16:07:48.016Z
Reserved: 2022-09-14T00:00:00.000Z
Link: CVE-2022-40223
Updated: 2024-08-03T12:14:39.953Z
Status : Modified
Published: 2022-11-08T19:15:14.647
Modified: 2024-11-21T07:21:05.980
Link: CVE-2022-40223
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD