← WordPress Vulnerabilities
WordPress security by component

elasticpress

elasticpress integrates WordPress search with Elasticsearch to provide indexed and enhanced content searching.

elasticpress (elasticpress) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 5.3.

Plugin slug: elasticpress

CVE-2026-62088: ElasticPress: A security weakness

ElasticPress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 5.3.4.

PublishedSep 11, 2026
Known safe version5.3.5
Published vulnerabilities for elasticpress
Safe version
Sep 11, 2026 CVE-2026-62088
ElasticPress: A security weakness
ElasticPress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 5.3.4.
5.3.5
CVE5.3
NVDPending
Jun 08, 2024 CVE-2024-35684
ElasticPress: Cross-site request forgery
ElasticPress is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Jul 01, 2023 CVE-2021-4405
ElasticPress: Cross-site request forgery
ElasticPress is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending