Description
WordPress Plugin Ajax Search Pro is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently insert a new user with administrative privileges. WordPress Plugin Ajax Search Pro version 3.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.0 or latest
References
http://research.evex.pw/?vuln=9
http://packetstormsecurity.com/files/130955/WordPress-Ajax-Search-Pro-Remote-Code-Execution.html
Related Vulnerabilities
PrestaShop Improper Privilege Management Vulnerability (CVE-2023-43663)
WordPress Plugin WooCommerce PHP Object Injection (3.2.3)
MySQL CVE-2016-3486 Vulnerability (CVE-2016-3486)
WordPress Plugin WP Cerber Security, Anti-spam & Malware Scan Security Bypass (8.9)
WordPress Plugin Chamber Dashboard Business Directory Cross-Site Scripting (3.2.8)