Unauthenticated Plugin Settings Change in Advance WordPress Search Plugin
A significant security flaw has been found in the Advance WordPress Search Plugin, identified as a Broken Authentication vulnerability (CVE-2022-40218). This issue allows unauthorized users, meaning anyone without needing to log in, to potentially alter the plugin’s settings. This kind of vulnerability can open the door for malicious actors to gain control over certain aspects of your website, posing a risk to your site’s integrity and security.
CVE Details
Product: Advance WordPress Search Plugin
Published: May 8, 2024
Severity: Medium
Status: Analyzed
Affected Products
The vulnerability impacts the ThemeHunk Advance WordPress Search Plugin. Specifically, all versions from its initial release up to and including version 1.1.4 are affected. If you are running any version within this range, your website is at risk.
Current Status
This vulnerability has been thoroughly analyzed, confirming its presence and potential impact. Details have been made public to ensure that users are aware and can take necessary steps to protect their systems.
Severity Level
Rated as Medium severity with a CVSS score of 6.5, this vulnerability could allow an attacker to make unauthenticated changes to plugin settings. While it might not immediately lead to full system compromise, unauthorized modifications can severely disrupt your website’s functionality, lead to data manipulation, or be a stepping stone for more severe attacks.
Possible Solutions
The most crucial step to secure your website against this vulnerability is to update your Advance WordPress Search Plugin. A fix has been released in version 1.1.5. Therefore, we strongly recommend updating your plugin to version 1.1.5 or any later version immediately. Keeping your plugins updated is a fundamental practice in maintaining a secure WordPress environment.
References
https://patchstack.com/database/vulnerability/th-advance-product-search/wordpress-th-advance-product-search-plugin-1-1-4-unauthenticated-plugin-settings-change-vulnerability?_s_id=cve
https://patchstack.com/database/vulnerability/th-advance-product-search/wordpress-th-advance-product-search-plugin-1-1-4-unauthenticated-plugin-settings-change-vulnerability?_s_id=cve


