WordPress security by component
Search Exclude
Plugin description
Search Exclude is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Nov 25, 2025; the highest CVE/CNA score is 7.5.
Plugin slug:
search-excludeLatest vulnerability
CVE-2025-10646: Search Exclude: A security weakness
Search Exclude is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
| Safe version |
|
||
|---|---|---|---|
| Nov 25, 2025 |
CVE-2025-10646
Search Exclude: A security weakness
Search Exclude is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| May 07, 2025 |
CVE-2025-2821
Search Exclude: A security weakness
Search Exclude is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Aug 23, 2022 |
CVE-2022-36282
Search Exclude: Cross-site scripting
Search Exclude is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVD5.4
|
| Sep 09, 2019 |
CVE-2019-15895
Search Exclude: A security weakness
Search Exclude is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVD7.5
|