6 results (0.009 seconds)

CVSS: 6.4EPSS: 0%CPEs: 1EXPL: 0

04 Mar 2025 — The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siq_searchbox' shortcode in all versions up to, and including, 4.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. El complemento SearchIQ – The Search Soluti... • https://plugins.trac.wordpress.org/browser/searchiq/trunk/library/shortcode.php#L132 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.0EPSS: 0%CPEs: 1EXPL: 0

19 Dec 2024 — Cross-Site Request Forgery (CSRF) vulnerability in Searchiq SearchIQ.This issue affects SearchIQ: from n/a through 4.6. Vulnerabilidad de Cross-Site Request Forgery (CSRF) en Searchiq SearchIQ. Este problema afecta a SearchIQ: desde n/a hasta 4.6. The SearchIQ plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.6. This is due to missing or incorrect nonce validation in the error-log.php file. • https://patchstack.com/database/wordpress/plugin/searchiq/vulnerability/wordpress-searchiq-plugin-4-6-cross-site-requst-forgery-csrf-vulnerability?_s_id=cve • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 6.4EPSS: 0%CPEs: 1EXPL: 0

03 Dec 2024 — The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siq_searchbox' shortcode in all versions up to, and including, 4.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. • https://plugins.trac.wordpress.org/browser/searchiq/tags/4.6/library/shortcode.php#L66 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

05 Apr 2024 — Insertion of Sensitive Information into Log File vulnerability in Searchiq SearchIQ.This issue affects SearchIQ: from n/a through 4.5. The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5 via log files. This makes it possible for unauthenticated attackers to extract sensitive data from log files. • https://patchstack.com/database/vulnerability/searchiq/wordpress-searchiq-plugin-4-5-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-532: Insertion of Sensitive Information into Log File •

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 0

16 Nov 2023 — Missing Authorization vulnerability in searchiq SearchIQ allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SearchIQ: from n/a through 4.4. The SearchIQ plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the getSIQPluginSettings function in versions up to, and including, 4.4. This makes it possible for unauthenticated attackers to view information such as the plugin settings, theme, and WordPress and PHP version. • https://patchstack.com/database/wordpress/plugin/searchiq/vulnerability/wordpress-searchiq-plugin-4-4-broken-access-control-vulnerability?_s_id=cve • CWE-862: Missing Authorization •

CVSS: 7.2EPSS: 0%CPEs: 1EXPL: 1

11 Apr 2022 — The SearchIQ WordPress plugin before 3.9 contains a flag to disable the verification of CSRF nonces, granting unauthenticated attackers access to the siq_ajax AJAX action and allowing them to perform Cross-Site Scripting attacks due to the lack of sanitisation and escaping in the customCss parameter El plugin SearchIQ de WordPress versiones anteriores a 3.9, contiene un flag para deshabilitar la verificación de los nonces de tipo CSRF, lo que permite a atacantes no autenticados acceder a la acción siq_ajax ... • https://wpscan.com/vulnerability/0ee7d1a8-9782-4db5-b055-e732f2763825 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •