Searchwp develops a focused WordPress search-enhancement plugin suite centered on its core search product and live AJAX search functionality. The durable vulnerability signal reflects authorization and access-control weaknesses, including user-controlled key handling and missing authorization checks, which are characteristic of plugin-layer permission validation in WordPress ecosystems. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Searchwp over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2535MEDIUM The SearchWP Live Ajax Search WordPress plugin before 1.6.2 does not ensure that users making a live search are limited to published posts only, allowing unauthenticated users to m | Aug 15, 2022 | 5.3 | 23 | NO | YES |
CVE-2022-40223MEDIUM Nonce token leakage and missing authorization in SearchWP premium plugin <= 4.2.5 on WordPress leading to plugin settings change. | Nov 8, 2022 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Searchwp.
Media articles that mention a CVE ID that affects a product developed by Searchwp — matched by CVE ID, not by vendor name.