Advance WordPress Search Plugin Broken Authentication Vulnerability (CVE-2022-40218) — Medium Severity

Unauthenticated Plugin Settings Change in Advance WordPress Search Plugin

A significant security flaw has been found in the Advance WordPress Search Plugin, identified as a Broken Authentication vulnerability (CVE-2022-40218). This issue allows unauthorized users, meaning anyone without needing to log in, to potentially alter the plugin’s settings. This kind of vulnerability can open the door for malicious actors to gain control over certain aspects of your website, posing a risk to your site’s integrity and security.

CVE Details

Product: Advance WordPress Search Plugin
Published: May 8, 2024
Severity: Medium
Status: Analyzed

Affected Products

The vulnerability impacts the ThemeHunk Advance WordPress Search Plugin. Specifically, all versions from its initial release up to and including version 1.1.4 are affected. If you are running any version within this range, your website is at risk.

Current Status

This vulnerability has been thoroughly analyzed, confirming its presence and potential impact. Details have been made public to ensure that users are aware and can take necessary steps to protect their systems.

Severity Level

Rated as Medium severity with a CVSS score of 6.5, this vulnerability could allow an attacker to make unauthenticated changes to plugin settings. While it might not immediately lead to full system compromise, unauthorized modifications can severely disrupt your website’s functionality, lead to data manipulation, or be a stepping stone for more severe attacks.

Possible Solutions

The most crucial step to secure your website against this vulnerability is to update your Advance WordPress Search Plugin. A fix has been released in version 1.1.5. Therefore, we strongly recommend updating your plugin to version 1.1.5 or any later version immediately. Keeping your plugins updated is a fundamental practice in maintaining a secure WordPress environment.

References

https://patchstack.com/database/vulnerability/th-advance-product-search/wordpress-th-advance-product-search-plugin-1-1-4-unauthenticated-plugin-settings-change-vulnerability?_s_id=cve
https://patchstack.com/database/vulnerability/th-advance-product-search/wordpress-th-advance-product-search-plugin-1-1-4-unauthenticated-plugin-settings-change-vulnerability?_s_id=cve

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.