Junglewise Threat Intelligence

CVE-2026-84821: WP Fast Total Search broken access control

CVE-2026-84821 · Severity: high · CVSS 7.5 · Published 2026-09-10

Technologies: Epsiloncool WP Fast Total Search. Vendors: Epsiloncool.

Executive brief

WP Fast Total Search is a WordPress plugin that provides search functionality for WordPress sites. An unauthenticated attacker can bypass access controls to view or access data they should not have permission to see, potentially exposing sensitive information to unauthorized users without requiring any credentials or authentication.

Technical details

This vulnerability is a broken access control flaw in the WP Fast Total Search WordPress plugin (versions <= 1.82.284) that allows unauthenticated attackers to access restricted functionality and data. The vulnerability does not require authentication or user interaction—an attacker can directly access protected resources over the network. By exploiting this flaw, an attacker can view or manipulate data that should be restricted to authorized users, leading to unauthorized information disclosure. The vulnerability has been patched in version 1.83.286 and later.

Affected products

  • Epsiloncool WP Fast Total Search <= 1.82.284

Timeline

  • 2026-09-09: disclosed
  • 2026-09-09: patched: Version 1.83.286

References

Related threats