CVE · Medium

CVE-2022-38456 — Ajax Search Lite – Live Search & Filter [ajax-search-lite] < 4.11.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-38456 Ajax Search Lite – Live Search & Filter [ajax-search-lite] < 4.11.1 Exposure of Sensitive Information to an Unauthorized Actor Medium 4.3 < 4.11.1 4.11.1 2023-02-06

CVE-2022-38456

The Ajax Search Lite plugin before version 4.11.1 contains an authorization flaw in its searchCF function that exposes an unprotected Ajax endpoint. Users with subscriber-level access can exploit this weakness to retrieve sensitive information, including post metadata, that should not be publicly accessible. The vulnerability affects all versions up through 4.10.3 and was resolved in version 4.11.1.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.