cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forsearch-exclude search-exclude

Direction: descending
Dec 11, 2025

Search Exclude # CVE-2025-10646

CVE, Research URL

CVE-2025-10646

Application

Search Exclude

Date
Nov 25, 2025
Research Description
The Search Exclude plugin for WordPress is vulnerable to unauthorized modification of data due to a insufficient capability check on the Base::get_rest_permission() method in all versions up to, and including, 2.5.7. This makes it possible for authenticated attackers, with Contributor-level access and above, to modify plugin settings, such as adding arbitrary posts to the search exclusion list.
Affected versions
max 2.5.8.
Status
vulnerable
May 07, 2025

Search Exclude # CVE-2025-2821

CVE, Research URL

CVE-2025-2821

Application

Search Exclude

Date
May 07, 2025
Research Description
The Search Exclude plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the get_rest_permission function in all versions up to, and including, 2.4.9. This makes it possible for unauthenticated attackers to modify plugin settings, excluding content from search results.
Affected versions
max 2.5.0.
Status
vulnerable
Jun 06, 2024

Search Exclude # CVE-2019-15895

CVE, Research URL

CVE-2019-15895

Application

Search Exclude

Date
Sep 09, 2019
Research Description
search-exclude.php in the "Search Exclude" plugin before 1.2.4 for WordPress allows unauthenticated options changes.
Affected versions
max 1.2.4.
Status
vulnerable

Search Exclude # CVE-2022-36282

CVE, Research URL

CVE-2022-36282

Application

Search Exclude

Date
Aug 23, 2022
Research Description
Authenticated (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Roman Pronskiy's Search Exclude plugin <= 1.2.6 at WordPress.
Affected versions
max 1.2.7.
Status
vulnerable