10up

Elasticpress

4 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Veröffentlicht 11.09.2026 18:26:40
  • Zuletzt bearbeitet 11.09.2026 21:17:11

Insertion of Sensitive Information Into Sent Data vulnerability in 10up ElasticPress allows Retrieve Embedded Sensitive Data. This issue affects ElasticPress: from n/a through 5.3.4.

  • EPSS 0.19%
  • Veröffentlicht 08.06.2024 15:15:50
  • Zuletzt bearbeitet 23.04.2026 15:18:30

Cross-Site Request Forgery (CSRF) vulnerability in 10up ElasticPress elasticpress.This issue affects ElasticPress: from n/a through <= 5.1.1.

  • EPSS 0.35%
  • Veröffentlicht 04.06.2024 11:15:50
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Authentication Bypass by Spoofing vulnerability in 10up Restricted Site Access allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Restricted Site Access: from n/a through 7.4.1.

  • EPSS 0.39%
  • Veröffentlicht 01.07.2023 06:15:10
  • Zuletzt bearbeitet 08.04.2026 18:17:19

The ElasticPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.3. This is due to missing or incorrect nonce validation on the epio_send_autosuggest_allowed() function. This makes it possible fo...