
CVE-2024-13350 – SearchIQ – The Search Solution <= 4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2024-13350
04 Mar 2025 — The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siq_searchbox' shortcode in all versions up to, and including, 4.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. El complemento SearchIQ – The Search Soluti... • https://plugins.trac.wordpress.org/browser/searchiq/trunk/library/shortcode.php#L132 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-56229 – WordPress SearchIQ plugin <= 4.6 - Cross-Site Requst Forgery (CSRF) vulnerability
https://notcve.org/view.php?id=CVE-2024-56229
19 Dec 2024 — Cross-Site Request Forgery (CSRF) vulnerability in Searchiq SearchIQ.This issue affects SearchIQ: from n/a through 4.6. Vulnerabilidad de Cross-Site Request Forgery (CSRF) en Searchiq SearchIQ. Este problema afecta a SearchIQ: desde n/a hasta 4.6. The SearchIQ plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.6. This is due to missing or incorrect nonce validation in the error-log.php file. • https://patchstack.com/database/wordpress/plugin/searchiq/vulnerability/wordpress-searchiq-plugin-4-6-cross-site-requst-forgery-csrf-vulnerability?_s_id=cve • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2024-10885 – SearchIQ – The Search Solution <= 4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2024-10885
03 Dec 2024 — The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siq_searchbox' shortcode in all versions up to, and including, 4.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. • https://plugins.trac.wordpress.org/browser/searchiq/tags/4.6/library/shortcode.php#L66 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-31259 – WordPress SearchIQ plugin <= 4.5 - Sensitive Data Exposure via Log File vulnerability
https://notcve.org/view.php?id=CVE-2024-31259
05 Apr 2024 — Insertion of Sensitive Information into Log File vulnerability in Searchiq SearchIQ.This issue affects SearchIQ: from n/a through 4.5. The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5 via log files. This makes it possible for unauthenticated attackers to extract sensitive data from log files. • https://patchstack.com/database/vulnerability/searchiq/wordpress-searchiq-plugin-4-5-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-532: Insertion of Sensitive Information into Log File •

CVE-2023-47832 – WordPress SearchIQ plugin <= 4.4 - Broken Access Control vulnerability
https://notcve.org/view.php?id=CVE-2023-47832
16 Nov 2023 — Missing Authorization vulnerability in searchiq SearchIQ allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SearchIQ: from n/a through 4.4. The SearchIQ plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the getSIQPluginSettings function in versions up to, and including, 4.4. This makes it possible for unauthenticated attackers to view information such as the plugin settings, theme, and WordPress and PHP version. • https://patchstack.com/database/wordpress/plugin/searchiq/vulnerability/wordpress-searchiq-plugin-4-4-broken-access-control-vulnerability?_s_id=cve • CWE-862: Missing Authorization •

CVE-2022-0780 – SearchIQ < 3.9 - Unauthenticated Stored XSS
https://notcve.org/view.php?id=CVE-2022-0780
11 Apr 2022 — The SearchIQ WordPress plugin before 3.9 contains a flag to disable the verification of CSRF nonces, granting unauthenticated attackers access to the siq_ajax AJAX action and allowing them to perform Cross-Site Scripting attacks due to the lack of sanitisation and escaping in the customCss parameter El plugin SearchIQ de WordPress versiones anteriores a 3.9, contiene un flag para deshabilitar la verificación de los nonces de tipo CSRF, lo que permite a atacantes no autenticados acceder a la acción siq_ajax ... • https://wpscan.com/vulnerability/0ee7d1a8-9782-4db5-b055-e732f2763825 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •