Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47845 | The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 5.5.6 via the ajax_load_posts function. This makes it possible for unauthenticated attackers to extract text data from password-protected posts using the boolean-based attack on the AJAX search form |
Wed, 11 Sep 2024 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:ivorysearch:ivory_search:*:*:*:*:*:wordpress:*:* |
Thu, 05 Sep 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ivorysearch
Ivorysearch ivory Search |
|
| CPEs | cpe:2.3:a:ivorysearch:ivory_search:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ivorysearch
Ivorysearch ivory Search |
|
| Metrics |
ssvc
|
Thu, 05 Sep 2024 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 5.5.6 via the ajax_load_posts function. This makes it possible for unauthenticated attackers to extract text data from password-protected posts using the boolean-based attack on the AJAX search form | |
| Title | Ivory Search – WordPress Search Plugin <= 5.5.6 - Information Exposure via AJAX Search Form | |
| Weaknesses | CWE-200 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:32:27.010Z
Reserved: 2024-07-17T15:03:14.463Z
Link: CVE-2024-6835
Updated: 2024-09-05T13:15:05.460Z
Status : Analyzed
Published: 2024-09-05T07:15:02.657
Modified: 2024-09-11T16:32:16.247
Link: CVE-2024-6835
No data.
OpenCVE Enrichment
No data.
EUVD