Vulnerabilities and security researches forsearch-exclude search-exclude
Direction: descendingMay 07, 2025
Search Exclude # CVE-2025-2821
- CVE, Research URL
- Home page URL
- Application
- Date
- May 07, 2025
- Research Description
- The Search Exclude plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the get_rest_permission function in all versions up to, and including, 2.4.9. This makes it possible for unauthenticated attackers to modify plugin settings, excluding content from search results.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Jun 06, 2024
Search Exclude # CVE-2019-15895
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 09, 2019
- Research Description
- search-exclude.php in the "Search Exclude" plugin before 1.2.4 for WordPress allows unauthenticated options changes.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Search Exclude # CVE-2022-36282
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 23, 2022
- Research Description
- Authenticated (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Roman Pronskiy's Search Exclude plugin <= 1.2.6 at WordPress.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable