
We found results for “”
CVE-2021-4405
Good to know:

Date: July 1, 2023
The ElasticPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.3. This is due to missing or incorrect nonce validation on the epio_send_autosuggest_allowed() function. This makes it possible for unauthenticated attackers to send allowed parameters for autosuggest to elasticpress[.]io via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Language: PHP
Severity Score
Related Resources (11)
Severity Score
Weakness Type (CWE)
Cross-Site Request Forgery (CSRF)
CWE-352Top Fix

Upgrade Version
Upgrade to version 10up/elasticpress - dev-fix/site-health-warning;10up/elasticpress - dev-feature/es-error-data;10up/elasticpress - dev-bug/multisite_context_switch_support;10up/elasticpress - dev-burhan/add-custom-results-e2e;10up/elasticpress - dev-feature/disable-autosuggest-selector;10up/elasticpress - dev-update-gh-action;10up/elasticpress - dev-trunk;10up/elasticpress - dev-fix/horizontal-scoll-on-status-report-page;10up/elasticpress - dev-fix/autosuggest-requests;10up/elasticpress - dev-github-issue-template;10up/elasticpress - dev-burhan/fix-1781;10up/elasticpress - dev-fix/remove-spl_object_hash-issue-1762;10up/elasticpress - dev-fix/do_sync-nonce;10up/elasticpress - dev-fix/cli-offset;10up/elasticpress - dev-fix/facets-op-within-widget;10up/elasticpress - dev-feature/theme-integration-docs;10up/elasticpress - dev-feature/skip-install;10up/elasticpress - dev-fix/deprecated-bottom-margin-warning;10up/elasticpress - dev-fix/number-of-expected-parameter;10up/elasticpress - dev-fix/search-while-full-sync;10up/elasticpress - dev-fix/plugin-uninstall;10up/elasticpress - dev-fix/woocommerce-order-search;10up/elasticpress - dev-feature/1690;10up/elasticpress - dev-revert-2004-patch-5;10up/elasticpress - dev-feature/validate-settings;10up/elasticpress - dev-filter-epas-request-args;10up/elasticpress - dev-fix/block-e2e-tests;10up/elasticpress - dev-feature/add-confirmation-for-destructive-wp-cli-issue-1713;10up/elasticpress - dev-fix/wpacceptance-json;10up/elasticpress - dev-fix/save-ir-template-after-index;10up/elasticpress - dev-fix/widgets-init;10up/elasticpress - dev-fix/1486-autosuggest-query;10up/elasticpress - dev-feature/1520-find-related-improvements;10up/elasticpress - dev-fix/dynamic-property-warning;10up/elasticpress - dev-feature/server-type-detection;10up/elasticpress - dev-upkeep/upload-artifact;10up/elasticpress - dev-fix/post-mime-type-issue-1604;10up/elasticpress - dev-feature/not-like-meta-query-issue-2015;10up/elasticpress - dev-feature/facet;10up/elasticpress - dev-revert-1007-fix/attachment-status;10up/elasticpress - dev-burhan/add-e2e-for-#2823;10up/elasticpress - dev-feature/algo-version-through-cli;10up/elasticpress - 3.5.4;10up/elasticpress - dev-bugfix/highlight-front-end;10up/elasticpress - dev-add/docs;10up/elasticpress - dev-fix/weighting-on-admin;10up/elasticpress - dev-hotfix/instant-results-method-name;10up/elasticpress - dev-fix/price-filter-query;10up/elasticpress - dev-feature/meta-not-between;10up/elasticpress - dev-fix/move-failed-queries-class;10up/elasticpress - dev-fix/remove-extra-space;10up/elasticpress - dev-dependabot/npm_and_yarn/cypress/request-and-cypress-3.0.0;10up/elasticpress - dev-feature/sync-page-ui;10up/elasticpress - dev-fix/undefined-array;10up/elasticpress - dev-feature/issue-1503;10up/elasticpress - dev-fix/no-mapping-found-name-sortable-issue-2044;10up/elasticpress - dev-feature/tax-operator-and;10up/elasticpress - dev-feature/synonyms;10up/elasticpress - dev-feature/indexing-option-multisite;10up/elasticpress - dev-columbian-chris/develop;10up/elasticpress - dev-feature/cli-instant-results-template-commands;10up/elasticpress - dev-docs/update-and-fix;10up/elasticpress - dev-fix/1854;10up/elasticpress - dev-fix/endpoint-url-field-is-not-type-url;10up/elasticpress - dev-update/issue-templates;10up/elasticpress - dev-docs/ep_set_sort-filter;10up/elasticpress - dev-feature/enhanced-debugging;10up/elasticpress - dev-fix/build-docs;10up/elasticpress - dev-bugfix/remove-quick-bulk-edit;10up/elasticpress - dev-dependabot/npm_and_yarn/nanoid-3.2.0;10up/elasticpress - dev-fix/warning-on-health-page;10up/elasticpress - dev-rebecca/feature_password-protected-posts;10up/elasticpress - dev-fix/issue-1938;10up/elasticpress - dev-dependabot/composer/composer/composer-2.6.4;10up/elasticpress - dev-fix/facetable-queries;10up/elasticpress - dev-bugfix/weighting-fixes;10up/elasticpress - dev-fix/mapping-error-output;10up/elasticpress - 1.4;automattic/vip-go-mu-plugins - dev-fix/is_subscriptions_page-regex;automattic/vip-go-mu-plugins - dev-pavel_test
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | REQUIRED |
Scope (S): | UNCHANGED |
Confidentiality (C): | NONE |
Integrity (I): | LOW |
Availability (A): | NONE |