ZeroHour

CVE-2026-84821

moderate

Unauthenticated Broken Access Control in WP Fast Total Search WordPress Plugin

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-84821 is a missing-authorization (broken access control, CWE-862) flaw in the WP Fast Total Search WordPress plugin affecting all versions up to and including 1.82.284. A privileged function or endpoint in the plugin lacks a required capability check, so an unauthenticated remote attacker can invoke it directly over HTTP with no credentials or user interaction. Per the CVSS 3.1 score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), the attacker gains access to information intended for higher-privileged users, with high confidentiality impact but no integrity or availability impact. Any WordPress site running WP Fast Total Search version 1.82.284 or older is affected. No public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and there are no confirmed reports of in-the-wild exploitation.

What to do: Update WP Fast Total Search to a version later than 1.82.284 (the latest patched release) as soon as possible; if updating is not immediately possible, deactivate the plugin until it can be patched. Because the flaw requires no authentication, review web-server and WordPress access logs for unauthenticated requests to the plugin's endpoints as a precaution.

Affected
WP Fast Total Search (WordPress plugin)<= 1.82.284
Estimated exposure
moderate≈2,000–3,000 WordPress sites (plugin active-install listings are in the low thousands) — Estimate based on WordPress.org active-install counts for the WP Fast Total Search plugin, which report only a few thousand active installations, so exposure is limited to small-to-mid-sized WordPress deployments rather than a mass…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Broken Access Control in WP Fast Total Search <= 1.82.284 versions.

Ecosystems
WordPress
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.