Junglewise Threat Intelligence

CVE-2026-57683: Epsiloncool WP Fast Total Search SQL injection

CVE-2026-57683 · Severity: critical · CVSS 9.3 · Published 2026-07-02

Technologies: Epsiloncool WP Fast Total Search. Vendors: Epsiloncool.

Executive brief

WP Fast Total Search is a WordPress plugin used to provide high-performance search functionality for websites. A security flaw allows an unauthenticated attacker to interact directly with the website's database. This could lead to the theft of sensitive customer data, administrative credentials, or other private information stored on the server.

Technical details

A SQL injection vulnerability exists in the WP Fast Total Search plugin for WordPress due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is present in versions up to and including 1.80.280. An unauthenticated remote attacker can exploit this by sending specially crafted requests to the application, allowing for unauthorized database queries. This can result in the extraction of sensitive information or impact to database integrity. The issue has been addressed in version 1.81.282.

Affected products

  • Epsiloncool WP Fast Total Search <= 1.80.280

Timeline

  • 2026-04-27: other: Reported by HaiND
  • 2026-06-29: advisory: Patchstack advisory published
  • 2026-07-02: disclosed: NVD publication date

References

Related threats