Executive brief
WP Fast Total Search, a WordPress plugin used to provide high-speed search functionality for websites, contains a security flaw that allows unauthorized users to perform actions they should not have access to. An attacker could exploit this to modify certain site settings or data without needing to log in. While the impact is currently rated as medium, it could lead to unauthorized changes to how the site handles search queries or internal data.
Technical details
The WP Fast Total Search plugin for WordPress is vulnerable to broken access control due to missing authorization checks (CWE-862) in versions up to and including 1.81.282. This vulnerability allows an unauthenticated remote attacker to execute functions or actions that should be restricted to higher-privileged users. The attack vector is network-based and requires no user interaction or prior authentication. According to the advisory, there is currently no official patch available, and the vulnerability could potentially be used in mass-exploit campaigns targeting WordPress sites.
Affected products
- Epsiloncool WP Fast Total Search <= 1.81.282
Timeline
- 2025-10-28: disclosed: Vulnerability reported by Que Thanh Tuan
- 2026-07-23: advisory: NVD and Patchstack published the advisory