CVE · Medium

CVE-2025-48099 — Search & Filter [search-filter] < 1.2.18

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-48099 Search & Filter [search-filter] < 1.2.18 Cross-Site Request Forgery (CSRF) Medium 4.7 < 1.2.18 1.2.18 2025-10-07

CVE-2025-48099

The Search & Filter plugin for WordPress contains a security flaw that allows malicious individuals to deceive administrators into carrying out unintended actions by exploiting a weakness in the validation process of certain functions, specifically those related to nonces. This vulnerability affects all versions up to and including 1.2.17. As a result, attackers can potentially execute unauthorized operations without needing authentication.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.