VYPR

AjaxSearchPro

by WordPress

CVEs (3)

  • CVE-2021-29654HigApr 14, 2021
    risk 0.47cvss 7.2epss 0.02

    AjaxSearchPro before 4.20.8 allows Deserialization of Untrusted Data (in the import database feature of the administration panel), leading to Remote Code execution.

  • CVE-2023-1435MedApr 24, 2023
    risk 0.40cvss 6.1epss 0.00

    The Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise and escape various parameters before outputting them back in pages, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

  • CVE-2023-1420MedApr 24, 2023
    risk 0.40cvss 6.1epss 0.00

    The Ajax Search Lite WordPress plugin before 4.11.1, Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise and escape a parameter before outputting it back in a response of an AJAX action, leading to a Reflected Cross-Site Scripting which could be used against high…