ElasticPress

ElasticPress, a search and query engine for WordPress, offers a variety of customizable features to improve content relevancy and speed up search results. The plugin includes features for popular plugins such as WooCommerce, related posts, protected content, and autosuggest. ElasticPress bypasses WordPress for optimal performance and can deliver results up to 10x faster than previous versions. The plugin also indexes text inside popular file types and provides controls to filter content by taxonomies.

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Input validation vulnerability in ElasticPress 5.1.0

    Fixed

    The ElasticPress plugin for WordPress has a security issue called Cross-Site Request Forgery. This means that even in the latest version, 5.1.0, there is a risk of unauthorized access. This happens b...

    Read More
  • Input validation vulnerability in ElasticPress 3.5.3

    Fixed

    The ElasticPress plugin for WordPress is vulnerable to a type of attack called Cross-Site Request Forgery. This affects versions 3.5.3 and earlier. The issue is caused by the epio_send_autosuggest_al...

    Read More
  • Access violation vulnerability in ElasticPress 4.1.0

    Fixed

    The Javascript library moment.js, which is used by many websites, has been found to have a security vulnerability in versions up to and including 2.29.1. This vulnerability can allow attackers to acc...

    Read More
  • Denial of Service vulnerability in terser package (5 plugins affected)

    Fixed

    The package terser

    Read More
  • Denial of Service vulnerability in package loader-utils (4 plugins affected)

    Fixed

    Certain versions of the package loader-utils (from version 1.4.2 to 2.0.4 and from 3.0.0 to 3.2.1) have a security issue that could potentially be exploited to cause a 'Denial of Service'. Some WordPr...

    Read More
  • Access violation vulnerability in Restricted Site Access 7.3.5

    Fixed

    The webpack package

    Read More
  • Denial of Service vulnerability in package loader-utils (4 plugins affected)

    Fixed

    An old version of a package called loader-utils

    Read More
  • Input validation vulnerability in simple-git package (5 plugins affected)

    Fixed

    The package called simple-git is not secure in versions before 3.15.0. It can be used to run remote code

    Read More
  • Input validation vulnerability in package loader-utils (3 plugins affected)

    Fixed

    An older version of the package loader-utils

    Read More
  • Input validation vulnerability in 68 different plugins

    Fixed

    Around 70 different plugins and themes had a security issue that could let someone else do something on the website without permission. The problem was that the system that was meant to stop this fro...

    Read More