The Ajax Search Lite WordPress plugin before 4.12.1 does...
Moderate severity
Unreviewed
Published
Aug 6, 2024
to the GitHub Advisory Database
•
Updated May 28, 2025
Description
Published by the National Vulnerability Database
Aug 6, 2024
Published to the GitHub Advisory Database
Aug 6, 2024
Last updated
May 28, 2025
The Ajax Search Lite WordPress plugin before 4.12.1 does not sanitise and escape some parameters, which could allow users with a role as low as Admin+ to perform Cross-Site Scripting attacks.
References