Description

WordPress Plugin Ajax Search Pro is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently insert a new user with administrative privileges. WordPress Plugin Ajax Search Pro version 3.5 is vulnerable; prior versions may also be affected.

Remediation

Update to plugin version 4.0 or latest

References

Related Vulnerabilities

Severity

High

Classification

CWE-264

Tags

Missing Update Authentication Bypass