icon

We found results for “

CVE-2021-4405

Good to know:

icon

Date: July 1, 2023

The ElasticPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.3. This is due to missing or incorrect nonce validation on the epio_send_autosuggest_allowed() function. This makes it possible for unauthenticated attackers to send allowed parameters for autosuggest to elasticpress[.]io via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Language: PHP

Severity Score

Severity Score

Weakness Type (CWE)

Cross-Site Request Forgery (CSRF)

CWE-352

Top Fix

icon

Upgrade Version

Upgrade to version 10up/elasticpress - dev-fix/site-health-warning;10up/elasticpress - dev-feature/es-error-data;10up/elasticpress - dev-bug/multisite_context_switch_support;10up/elasticpress - dev-burhan/add-custom-results-e2e;10up/elasticpress - dev-feature/disable-autosuggest-selector;10up/elasticpress - dev-update-gh-action;10up/elasticpress - dev-trunk;10up/elasticpress - dev-fix/horizontal-scoll-on-status-report-page;10up/elasticpress - dev-fix/autosuggest-requests;10up/elasticpress - dev-github-issue-template;10up/elasticpress - dev-burhan/fix-1781;10up/elasticpress - dev-fix/remove-spl_object_hash-issue-1762;10up/elasticpress - dev-fix/do_sync-nonce;10up/elasticpress - dev-fix/cli-offset;10up/elasticpress - dev-fix/facets-op-within-widget;10up/elasticpress - dev-feature/theme-integration-docs;10up/elasticpress - dev-feature/skip-install;10up/elasticpress - dev-fix/deprecated-bottom-margin-warning;10up/elasticpress - dev-fix/number-of-expected-parameter;10up/elasticpress - dev-fix/search-while-full-sync;10up/elasticpress - dev-fix/plugin-uninstall;10up/elasticpress - dev-fix/woocommerce-order-search;10up/elasticpress - dev-feature/1690;10up/elasticpress - dev-revert-2004-patch-5;10up/elasticpress - dev-feature/validate-settings;10up/elasticpress - dev-filter-epas-request-args;10up/elasticpress - dev-fix/block-e2e-tests;10up/elasticpress - dev-feature/add-confirmation-for-destructive-wp-cli-issue-1713;10up/elasticpress - dev-fix/wpacceptance-json;10up/elasticpress - dev-fix/save-ir-template-after-index;10up/elasticpress - dev-fix/widgets-init;10up/elasticpress - dev-fix/1486-autosuggest-query;10up/elasticpress - dev-feature/1520-find-related-improvements;10up/elasticpress - dev-fix/dynamic-property-warning;10up/elasticpress - dev-feature/server-type-detection;10up/elasticpress - dev-upkeep/upload-artifact;10up/elasticpress - dev-fix/post-mime-type-issue-1604;10up/elasticpress - dev-feature/not-like-meta-query-issue-2015;10up/elasticpress - dev-feature/facet;10up/elasticpress - dev-revert-1007-fix/attachment-status;10up/elasticpress - dev-burhan/add-e2e-for-#2823;10up/elasticpress - dev-feature/algo-version-through-cli;10up/elasticpress - 3.5.4;10up/elasticpress - dev-bugfix/highlight-front-end;10up/elasticpress - dev-add/docs;10up/elasticpress - dev-fix/weighting-on-admin;10up/elasticpress - dev-hotfix/instant-results-method-name;10up/elasticpress - dev-fix/price-filter-query;10up/elasticpress - dev-feature/meta-not-between;10up/elasticpress - dev-fix/move-failed-queries-class;10up/elasticpress - dev-fix/remove-extra-space;10up/elasticpress - dev-dependabot/npm_and_yarn/cypress/request-and-cypress-3.0.0;10up/elasticpress - dev-feature/sync-page-ui;10up/elasticpress - dev-fix/undefined-array;10up/elasticpress - dev-feature/issue-1503;10up/elasticpress - dev-fix/no-mapping-found-name-sortable-issue-2044;10up/elasticpress - dev-feature/tax-operator-and;10up/elasticpress - dev-feature/synonyms;10up/elasticpress - dev-feature/indexing-option-multisite;10up/elasticpress - dev-columbian-chris/develop;10up/elasticpress - dev-feature/cli-instant-results-template-commands;10up/elasticpress - dev-docs/update-and-fix;10up/elasticpress - dev-fix/1854;10up/elasticpress - dev-fix/endpoint-url-field-is-not-type-url;10up/elasticpress - dev-update/issue-templates;10up/elasticpress - dev-docs/ep_set_sort-filter;10up/elasticpress - dev-feature/enhanced-debugging;10up/elasticpress - dev-fix/build-docs;10up/elasticpress - dev-bugfix/remove-quick-bulk-edit;10up/elasticpress - dev-dependabot/npm_and_yarn/nanoid-3.2.0;10up/elasticpress - dev-fix/warning-on-health-page;10up/elasticpress - dev-rebecca/feature_password-protected-posts;10up/elasticpress - dev-fix/issue-1938;10up/elasticpress - dev-dependabot/composer/composer/composer-2.6.4;10up/elasticpress - dev-fix/facetable-queries;10up/elasticpress - dev-bugfix/weighting-fixes;10up/elasticpress - dev-fix/mapping-error-output;10up/elasticpress - 1.4;automattic/vip-go-mu-plugins - dev-fix/is_subscriptions_page-regex;automattic/vip-go-mu-plugins - dev-pavel_test

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): REQUIRED
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): LOW
Availability (A): NONE

Do you need more information?

Contact Us