Description
The Ajax Search Lite WordPress plugin before 4.12.1 does not sanitise and escape some parameters, which could allow users with a role as low as Admin+ to perform Cross-Site Scripting attacks.
Published: 2024-08-06
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 28 May 2025 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Wp-dreams
Wp-dreams ajax Search
Weaknesses CWE-79
CPEs cpe:2.3:a:wp-dreams:ajax_search:*:*:*:*:lite:wordpress:*:*
Vendors & Products Wp-dreams
Wp-dreams ajax Search

Fri, 01 Nov 2024 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Ajax Search Project
Ajax Search Project ajax Search
CPEs cpe:2.3:a:ajax_search_project:ajax_search:*:*:*:*:lite:wordpress:*:*
Vendors & Products Ajax Search Project
Ajax Search Project ajax Search
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Ajax Search Project Ajax Search
Wp-dreams Ajax Search
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2024-11-01T20:44:09.200Z

Reserved: 2024-07-24T16:58:07.625Z

Link: CVE-2024-7084

cve-icon Vulnrichment

Updated: 2024-08-06T14:20:24.924Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-06T06:15:36.480

Modified: 2025-05-28T19:41:14.140

Link: CVE-2024-7084

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses