Input validation vulnerability in WordPress WP-Advanced-Search 3.3.4

The WordPress WP-Advanced-Search plugin, up to and including version 3.3.3, has a security vulnerability that can allow unauthenticated attackers to run code on the server. This happens because the WP_Advanced_Search_Import() function is hooked to an action that is accessible to all users. This action allows the attackers to upload a file, which then allows them to run code on the server.

Detected in:

WordPress WP-Advanced-Search open vulnerable versions: >= * < 3.3.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.