CVE Database /
CVE-2022-38456
CVE · Medium
CVE-2022-38456 — Ajax Search Lite – Live Search & Filter [ajax-search-lite] < 4.11.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-38456
|
Ajax Search Lite – Live Search & Filter [ajax-search-lite] < 4.11.1 |
Exposure of Sensitive Information to an Unauthorized Actor |
Medium
4.3
|
< 4.11.1
|
4.11.1 |
2023-02-06 |
—
|
CVE-2022-38456
The Ajax Search Lite plugin before version 4.11.1 contains an authorization flaw in its searchCF function that exposes an unprotected Ajax endpoint. Users with subscriber-level access can exploit this weakness to retrieve sensitive information, including post metadata, that should not be publicly accessible. The vulnerability affects all versions up through 4.10.3 and was resolved in version 4.11.1.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings