Description
WordPress Plugin Ajax Search Lite is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently insert a new user with administrative privileges. WordPress Plugin Ajax Search Lite version 3.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.11 or latest
References
Related Vulnerabilities
WordPress Plugin Popup Maker-Popup for opt-ins, lead gen, & more Cross-Site Scripting (1.6.4)
phpMyAdmin Improper Input Validation Vulnerability (CVE-2016-9858)
WordPress Plugin WordPress Infinite Scroll-Ajax Load More SQL Injection (5.3.1)
Magento Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-7942)