Description
WordPress Plugin Ajax Search Lite is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently insert a new user with administrative privileges. WordPress Plugin Ajax Search Lite version 3.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.11 or latest
References
Related Vulnerabilities
WordPress Plugin HDInvoice-Create Invoices Arbitrary File Upload (0.1)
WordPress 5.7.x Multiple Vulnerabilities (5.7 - 5.7.6)
PostgreSQL Improper Input Validation Vulnerability (CVE-2012-3489)
WordPress Plugin Backup and Restore WordPress-WPBackItUp Cross-Site Request Forgery (1.6.7)
WordPress Plugin PhonePe Payment Solutions Server-Side Request Forgery (1.0.15)