Junglewise Threat Intelligence

CVE-2026-27418: Epsiloncool WP Fast Total Search broken access control

CVE-2026-27418 · Severity: medium · CVSS 5.3 · Published 2026-07-23

Technologies: Epsiloncool WP Fast Total Search. Vendors: Epsiloncool.

Executive brief

WP Fast Total Search, a WordPress plugin used to provide high-speed search functionality for websites, contains a security flaw that allows unauthorized users to perform actions they should not have access to. An attacker could exploit this to modify certain site settings or data without needing to log in. While the impact is currently rated as medium, it could lead to unauthorized changes to how the site handles search queries or internal data.

Technical details

The WP Fast Total Search plugin for WordPress is vulnerable to broken access control due to missing authorization checks (CWE-862) in versions up to and including 1.81.282. This vulnerability allows an unauthenticated remote attacker to execute functions or actions that should be restricted to higher-privileged users. The attack vector is network-based and requires no user interaction or prior authentication. According to the advisory, there is currently no official patch available, and the vulnerability could potentially be used in mass-exploit campaigns targeting WordPress sites.

Affected products

  • Epsiloncool WP Fast Total Search <= 1.81.282

Timeline

  • 2025-10-28: disclosed: Vulnerability reported by Que Thanh Tuan
  • 2026-07-23: advisory: NVD and Patchstack published the advisory

References

Related threats