Executive brief
WP Fast Total Search is a WordPress plugin that provides search functionality for WordPress sites. An unauthenticated attacker can bypass access controls to view or access data they should not have permission to see, potentially exposing sensitive information to unauthorized users without requiring any credentials or authentication.
Technical details
This vulnerability is a broken access control flaw in the WP Fast Total Search WordPress plugin (versions <= 1.82.284) that allows unauthenticated attackers to access restricted functionality and data. The vulnerability does not require authentication or user interaction—an attacker can directly access protected resources over the network. By exploiting this flaw, an attacker can view or manipulate data that should be restricted to authorized users, leading to unauthorized information disclosure. The vulnerability has been patched in version 1.83.286 and later.
Affected products
- Epsiloncool WP Fast Total Search <= 1.82.284
Timeline
- 2026-09-09: disclosed
- 2026-09-09: patched: Version 1.83.286