CVE-2024-6835: Ivory Search – WordPress Search Plugin <= 5.5.6 - Information Exposure via AJAX Search Form
The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 5.5.6 via the ajaxloadposts function. This makes it possible for unauthenticated attackers to extract text data from password-protected posts using the boolean-based attack on the AJAX search form
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6835?
CVE-2024-6835 is classified as a high-severity vulnerability due to its potential for information exposure.
How do I fix CVE-2024-6835?
To fix CVE-2024-6835, update the Ivory Search plugin to version 5.5.7 or later.
What systems are affected by CVE-2024-6835?
CVE-2024-6835 affects all versions of the Ivory Search plugin for WordPress up to and including version 5.5.6.
Can unauthenticated users exploit CVE-2024-6835?
Yes, unauthenticated attackers can exploit CVE-2024-6835 to extract text data from password-protected posts.
What function in the Ivory Search plugin is vulnerable in CVE-2024-6835?
The ajax_load_posts function in the Ivory Search plugin is the source of the vulnerability in CVE-2024-6835.