WordPress security by component
WP Fast Total Search
WP Fast Total Search (fulltext-search) is a WordPress plugin with 12 published CVE records in this archive. The latest tracked vulnerability was published Sep 10, 2026; the highest published CVSS base score is 9.3.
Plugin slug:
fulltext-searchLatest vulnerability
CVE-2026-84821: WP Fast Total Search exposes protected data without authorization
WP Fast Total Search through 1.82.284 has an unauthenticated missing-authorization flaw. The CNA rates confidentiality impact as high: an attacker needs neither an account nor another user's interaction to reach the affected protected data.
| Safe version |
|
||
|---|---|---|---|
| Sep 10, 2026 |
CVE-2026-84821
WP Fast Total Search exposes protected data without authorization
WP Fast Total Search through 1.82.284 has an unauthenticated missing-authorization flaw. The CNA rates confidentiality impact as high: an attacker needs neither an account nor another user's interaction to reach the affected protected data.
|
1.83.286 |
CVE7.5
NVDPending
|
| Jul 28, 2026 |
CVE-2026-12741
WP Fast Total Search exposes an unauthenticated SQL injection
WP Fast Total Search through 1.80.280 registers the wpfts_autocomplete AJAX action for logged-out visitors. wpfts_autocomplete_proc() copies attacker-controlled form_data[s] into a WP_Query, after which the plugin's SQL-building path incorporates search terms into queries without full parameterization. An unauthenticated attacker can alter those queries and extract sensitive database information. Version 1.81.282 replaces the vulnerable string construction with placeholders and $wpdb->prepare().
|
1.81.282 |
CVE7.5
NVDPending
|
| Jul 23, 2026 |
CVE-2026-27418
WP Fast Total Search: Broken access control
WP Fast Total Search is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 1.81.282.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jul 02, 2026 |
CVE-2026-57683
WP Fast Total Search: SQL injection
WP Fast Total Search is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 1.80.280.
|
1.81.282 |
CVE9.3
NVDPending
|
| Aug 22, 2025 |
CVE-2025-57893
WP Fast Total Search: Cross-site request forgery
WP Fast Total Search is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Mar 27, 2025 |
CVE-2025-30894
WP Fast Total Search: A security weakness
WP Fast Total Search is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jan 24, 2025 |
CVE-2025-24572
WP Fast Total Search: Cross-site request forgery
WP Fast Total Search is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Jan 24, 2025 |
CVE-2025-24571
WP Fast Total Search: A security weakness
WP Fast Total Search is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Jan 02, 2025 |
CVE-2024-38778
WP Fast Total Search: Cross-site request forgery
WP Fast Total Search is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Nov 01, 2024 |
CVE-2024-38714
WP Fast Total Search: A security weakness
WP Fast Total Search is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Aug 01, 2024 |
CVE-2024-39663
WP Fast Total Search: Cross-site scripting
WP Fast Total Search is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVDPending
|
| Mar 27, 2024 |
CVE-2024-29799
WP Fast Total Search: Cross-site scripting
WP Fast Total Search is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|