Executive brief
ElasticPress is a popular WordPress search plugin that indexes content for improved site search functionality. A vulnerability in versions up to 5.3.4 allows unauthorized parties to retrieve sensitive information (such as passwords, emails, or payment details) embedded in data sent by the plugin, potentially exposing customer or site data without requiring authentication.
Technical details
The vulnerability is classified as an insertion of sensitive information into sent data (CWE-95 or similar), where private information is unintentionally leaked through the plugin's outbound communication or API responses. The flaw affects ElasticPress versions through 5.3.4 and does not require authentication to exploit. An attacker on the network or monitoring outbound traffic could retrieve embedded sensitive data, leading to unauthorized disclosure of passwords, emails, payment information, or other confidential details. The issue is patched in version 5.3.5 and later.
Affected products
- 10up ElasticPress through 5.3.4
Timeline
- 2026-09-11: disclosed: Vulnerability published by Patchstack
- 2026-09-11: patched: Version 5.3.5 available