WordPress security by component
elasticpress
Plugin description
elasticpress integrates WordPress search with Elasticsearch to provide indexed and enhanced content searching.
elasticpress (elasticpress) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 5.3.
Plugin slug:
elasticpressLatest vulnerability
CVE-2026-62088: ElasticPress: A security weakness
ElasticPress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 5.3.4.
| Safe version |
|
||
|---|---|---|---|
| Sep 11, 2026 |
CVE-2026-62088
ElasticPress: A security weakness
ElasticPress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 5.3.4.
|
5.3.5 |
CVE5.3
NVDPending
|
| Jun 08, 2024 |
CVE-2024-35684
ElasticPress: Cross-site request forgery
ElasticPress is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Jul 01, 2023 |
CVE-2021-4405
ElasticPress: Cross-site request forgery
ElasticPress is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|