Junglewise Threat Intelligence

CVE-2026-27357: Cornel Raiu WP Search Analytics missing authorization

CVE-2026-27357 · Severity: medium · CVSS 5.3 · Published 2026-05-25

Executive brief

WP Search Analytics is a WordPress plugin used to track and analyze what visitors are searching for on a website. A security flaw in versions prior to 1.5.0 allows unauthorized individuals to bypass access controls due to missing authorization checks. This could allow an attacker to modify settings or perform actions that should be restricted to administrators, potentially disrupting how search data is collected or managed.

Technical details

A missing authorization vulnerability (CWE-862) exists in the Cornel Raiu WP Search Analytics plugin for WordPress in versions prior to 1.5.0. The vulnerability stems from a failure to implement proper access control checks on certain functions, allowing unauthenticated users to execute actions that should require higher privileges. An attacker can exploit this over the network without any user interaction. The impact is primarily limited to unauthorized integrity changes (CVSS:I:L), such as modifying plugin configurations. The issue is resolved in version 1.5.0.

Affected products

  • Cornel Raiu WP Search Analytics before 1.5.0

Timeline

  • 2025-11-26: other: Reported by Legion Hunter
  • 2026-05-25: patched: Version 1.5.0 released
  • 2026-05-25: disclosed: Published by Patchstack

References