Ivory Search – WordPress Search Plugin <= 5.5.5 - Missing Authorization to Authenticated (Subscriber+) Index Creation
Published May 2, 2024
4.3
MEDIUMCVSS 3.1
EPSS 0.45%
Description
The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_create_index() function in all versions up to, and including, 5.5.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to trigger index creation.
Affected products
-
- Version -StatusaffectedConstraints<=5.5.5
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Vinod-Dalvi | Ivory Search – WordPress Search Plugin | unaffected |
|
No data.
-
- Version 0StatusaffectedConstraints<=5.5.5
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Vinod-Dalvi | Ivory Search | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-31825 Advisory
- https://plugins.trac.wordpress.org/changeset/3067568/add-search-to-menu/trunk/includes/class-is-index-manager.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/cc9935d8-7790-457b-88bf-bee5e13b0f5a?source=cve
Change history (0)
No recorded changes yet.