Junglewise Threat Intelligence

CVE-2018-25434: WP AutoSuggest SQL injection in wpas_keys parameter

CVE-2018-25434 · Severity: high · CVSS 8.2 · Published 2026-06-01

Executive brief

WP AutoSuggest is a WordPress plugin used to provide search suggestions to website visitors. A security flaw in this plugin allows unauthenticated attackers to access and extract sensitive information from the website's database. This could lead to the exposure of private posts, user data, and other confidential site information, potentially compromising the entire website.

Technical details

An SQL injection vulnerability exists in WP AutoSuggest 0.24 within the autosuggest.php file. The root cause is the improper neutralization of the 'wpas_keys' GET parameter before it is used in a WordPress database query ($wpdb->get_results). An unauthenticated remote attacker can exploit this by sending a crafted GET request to the vulnerable endpoint, allowing them to bypass intended query logic and extract sensitive data from the WordPress database. The plugin has been closed on the WordPress repository and is no longer available for download; users should uninstall the plugin as no patch is available.

Affected products

  • eliekhoury WP AutoSuggest 0.24

Timeline

  • 2018-12-01: disclosed: Initial exploit discovery by Kaimi
  • 2018-12-11: other: Exploit published on Exploit-DB
  • 2019-01-07: other: Plugin closed on WordPress.org due to security issues
  • 2026-06-01: advisory: CVE published/updated in NVD

References