PT-2026-51681 · WordPress · Searchplus

·

CVE-2026-8617

·

Published

2026-06-24

·

Updated

2026-07-02

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions SearchPlus versions prior to 1.7.2
Description The SearchPlus plugin for WordPress allows unauthenticated users to modify or delete stored data. This occurs because the searchplus save token action callback() and searchplus reset token action callback() functions lack capability checks and nonce validation, and are exposed via wp ajax nopriv hooks. An attacker can exploit this to overwrite or delete account token and account name options, specifically the dym token, dym name, searchplus token, searchplus name, sp token, and sp name variables.
Recommendations Update SearchPlus to version 1.7.2 or later. As a temporary mitigation, restrict access to the searchplus save token action callback() and searchplus reset token action callback() functions.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8617

Affected Products

Searchplus