CVE-2026-84821: WordPress WP Fast Total Search plugin <= 1.82.284 - Broken Access Control vulnerability
Published Sep 10, 2026
·Updated
Unauthenticated Broken Access Control in WP Fast Total Search <= 1.82.284 versions.
Affected Software
1 affected component
WordPress WP Fast Total Search<=1.82.284
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP Fast Total Search Pluginto a version that resolves this vulnerability.Fixed in 1.83.286
Event History
Sep 10, 2026
CVE Published
via MITRE·02:23 PM
Data Sourced
via MITRE·02:23 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges. It is remotely reachable according to the network attack vector.
2
Which installations are affected?
Installations using WP Fast Total Search version 1.82.284 or earlier are affected. The provided data does not identify any configuration prerequisite or mitigation other than updating beyond the affected versions.