Access violation vulnerability in Predictive Search 1.2.2

The Predictive Search plugin for WordPress is vulnerable to data being seen without authorization. This means that people who are not supposed to view the data can see it. This issue affects versions of the plugin up to 1.2.2. The problem is that the ‘get_exclude_options_ajax’ function is called without first making sure that the person accessing it is allowed to do so. This makes it possible for unauthenticated attackers to retrieve the search data.

Detected in:

Predictive Search fixed vulnerable versions: >= * <= 1.2.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.