← WordPress Vulnerabilities
WordPress security by component

WP Fast Total Search

WP Fast Total Search is a WordPress component with 11 published CVE records in this archive. The latest tracked vulnerability was published Jul 28, 2026; the highest CVE/CNA score is 9.3.

Plugin slug: fulltext-search

CVE-2026-12741: WP Fast Total Search exposes an unauthenticated SQL injection

WP Fast Total Search through 1.80.280 registers the wpfts_autocomplete AJAX action for logged-out visitors. wpfts_autocomplete_proc() copies attacker-controlled form_data[s] into a WP_Query, after which the plugin's SQL-building path incorporates search terms into queries without full parameterization. An unauthenticated attacker can alter those queries and extract sensitive database information. The CNA record does not identify the exact records obtainable. Version 1.81.282 replaces the vulnerable string construction with placeholders and $wpdb->prepare().

PublishedJul 28, 2026
Known safe version1.81.282
Safe version
Jul 28, 2026 CVE-2026-12741
WP Fast Total Search exposes an unauthenticated SQL injection
WP Fast Total Search through 1.80.280 registers the wpfts_autocomplete AJAX action for logged-out visitors. wpfts_autocomplete_proc() copies attacker-controlled form_data[s] into a WP_Query, after which the plugin's SQL-building path incorporates search terms into queries without full parameterization. An unauthenticated attacker can alter those queries and extract sensitive database information. The CNA record does not identify the exact records obtainable. Version 1.81.282 replaces the vulnerable string construction with placeholders and $wpdb->prepare().
1.81.282
CVE7.5
NVDPending
Jul 23, 2026 CVE-2026-27418
WP Fast Total Search: A security weakness
WP Fast Total Search is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.81.282.
> 1.81.282
CVE5.3
NVDPending
Jul 02, 2026 CVE-2026-57683
WP Fast Total Search: SQL injection
WP Fast Total Search is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 1.80.280.
1.81.282
CVE9.3
NVDPending
Aug 22, 2025 CVE-2025-57893
WP Fast Total Search: Cross-site request forgery
WP Fast Total Search is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Mar 27, 2025 CVE-2025-30894
WP Fast Total Search: A security weakness
WP Fast Total Search is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Jan 24, 2025 CVE-2025-24572
WP Fast Total Search: Cross-site request forgery
WP Fast Total Search is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE6.5
NVDPending
Jan 24, 2025 CVE-2025-24571
WP Fast Total Search: A security weakness
WP Fast Total Search is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending
Jan 02, 2025 CVE-2024-38778
WP Fast Total Search: Cross-site request forgery
WP Fast Total Search is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Nov 01, 2024 CVE-2024-38714
WP Fast Total Search: A security weakness
WP Fast Total Search is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Aug 01, 2024 CVE-2024-39663
WP Fast Total Search: Cross-site scripting
WP Fast Total Search is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Mar 27, 2024 CVE-2024-29799
WP Fast Total Search: Cross-site scripting
WP Fast Total Search is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending