CVE-2026-84821
moderateUnauthenticated Broken Access Control in WP Fast Total Search WordPress Plugin
CVE-2026-84821 is a missing-authorization (broken access control, CWE-862) flaw in the WP Fast Total Search WordPress plugin affecting all versions up to and including 1.82.284. A privileged function or endpoint in the plugin lacks a required capability check, so an unauthenticated remote attacker can invoke it directly over HTTP with no credentials or user interaction. Per the CVSS 3.1 score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), the attacker gains access to information intended for higher-privileged users, with high confidentiality impact but no integrity or availability impact. Any WordPress site running WP Fast Total Search version 1.82.284 or older is affected. No public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and there are no confirmed reports of in-the-wild exploitation.
What to do: Update WP Fast Total Search to a version later than 1.82.284 (the latest patched release) as soon as possible; if updating is not immediately possible, deactivate the plugin until it can be patched. Because the flaw requires no authentication, review web-server and WordPress access logs for unauthenticated requests to the plugin's endpoints as a precaution.
| WP Fast Total Search (WordPress plugin) | <= 1.82.284 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Broken Access Control in WP Fast Total Search <= 1.82.284 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.