WordPress Plugin Vulnerabilities

SearchWP Live Ajax Search < 1.6.3 - Unauthenticated Local File Inclusion

Description

The plugin does not validate the swpengine parameter of the searchwp_live_search AJAX action, which could allow unauthenticated attackers to perform Local File Inclusion attack via a Path Traversal vector on web server running IIS

Affects Plugins

References

Classification

Type
TRAVERSAL
OWASP top 10
CWE

Miscellaneous

Original Researcher
Muhammad Zeeshan (Xib3rR4dAr)
Verified
No

Timeline

Publicly Published
2022-09-15 (about 3 years ago)
Added
2022-09-16 (about 3 years ago)
Last Updated
2022-09-16 (about 3 years ago)

Other