CVE-2024-3233: Ivory Search – WordPress Search Plugin <= 5.5.5 - Missing Authorization to Authenticated (Subscriber+) Index Creation
The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajaxcreateindex() function in all versions up to, and including, 5.5.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to trigger index creation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3233?
CVE-2024-3233 is considered a medium severity vulnerability due to unauthorized modification of data.
How do I fix CVE-2024-3233?
To fix CVE-2024-3233, update the Ivory Search – WordPress Search Plugin to the latest version beyond 5.5.5.
Who is affected by CVE-2024-3233?
CVE-2024-3233 affects all versions of the Ivory Search – WordPress Search Plugin up to and including 5.5.5.
What type of attacks can occur due to CVE-2024-3233?
Authenticated attackers with subscriber-level access can exploit CVE-2024-3233 to modify data without proper authorization.
What is ajax_create_index() in relation to CVE-2024-3233?
The ajax_create_index() function is vulnerable in CVE-2024-3233 due to a missing capability check, allowing unauthorized data manipulation.