cleantalk
Vulnerabilities and Security Researches

Ajax Search Lite, CVE-2023-1420

CVE, Research URL

CVE-2023-1420

Application

Ajax Search Lite

Published on
Apr 25, 2023
Research Description
The Ajax Search Lite WordPress plugin before 4.11.1, Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise and escape a parameter before outputting it back in a response of an AJAX action, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected versions
max 4.11.1.
Status
vulnerable