VendorsInternet-Formationwp-advanced-searchany version
Vulnerabilities

Internet-Formation WP-Advanced-Search any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2024-9796
WP-Advanced-Search < 3.3.9.2 - Unauthenticated SQL Injection
Published 2024-10-10 · Analyzed
9.8EPSS 0.030
CVE-2020-12104
The Import feature in the wp-advanced-search plugin 3.3.6 for WordPress is vulnerable to authenticated SQL injection via an uploaded .sql file. An attacker can use this to execute SQL commands without any validation.
Published 2020-05-05 · Modified
8.8EPSS 0.016
CVE-2022-47447
WordPress WP-Advanced-Search Plugin <= 3.3.8 is vulnerable to Cross Site Request Forgery (CSRF)
Published 2023-05-24 · Modified
8.8EPSS 0.003
CVE-2024-10554
WP-Advanced-Search < 3.3.9.3 - Admin+ Stored XSS
Published 2025-03-25 · Analyzed
3.5EPSS 0.003