cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forsearch-analytics search-analytics

Direction: ascending
Jun 07, 2024

WP Search Analytics # CVE-2023-30471

CVE, Research URL

CVE-2023-30471

Application

WP Search Analytics

Date
Sep 27, 2023
Research Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Cornel Raiu WP Search Analytics plugin <= 1.4.7 versions.
Affected versions
max 1.4.8.
Status
vulnerable

WP Search Analytics # CVE-2022-47587

CVE, Research URL

CVE-2022-47587

Application

WP Search Analytics

Date
May 10, 2023
Research Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Cornel Raiu WP Search Analytics plugin <= 1.4.5 versions.
Affected versions
max 1.4.6.
Status
vulnerable
Aug 13, 2024

WP Search Analytics # CVE-2024-43229

CVE, Research URL

CVE-2024-43229

Application

WP Search Analytics

Date
Nov 01, 2024
Research Description
Missing Authorization vulnerability in Cornel Raiu WP Search Analytics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Search Analytics: from n/a through 1.4.9.
Affected versions
max 1.4.10.
Status
vulnerable
Oct 02, 2024

WP Search Analytics # CVE-2024-9209

CVE, Research URL

CVE-2024-9209

Application

WP Search Analytics

Date
Oct 01, 2024
Research Description
The WP Search Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.4.10. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 1.4.11.
Status
vulnerable
May 28, 2026

WP Search Analytics # CVE-2026-27357

CVE, Research URL

CVE-2026-27357

Application

WP Search Analytics

Date
May 26, 2026
Research Description
Missing Authorization vulnerability in Cornel Raiu WP Search Analytics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Search Analytics: from n/a before 1.5.0.
Affected versions
max 1.5.0.
Status
vulnerable