Search Everything
search-everything · plugin
Known security vulnerabilities for Search Everything. Find out in seconds which version runs on your site with WP Lens.
4 known vulnerabilities
2 critical · 2 exploitable without logging in · latest Aug 22, 2019
Listed on wordpress.org · latest 8.1.9 · last updated Nov 28, 2017 · 10K+ installs
Not updated since Nov 28, 2017. A component left without updates for over two years should not be expected to patch new vulnerabilities.
wordpress.org status checked on Oct 2, 2026
Vulnerabilities
- Critical 9.8
CVE-2017-18571unauthenticated
The search-everything plugin before 8.1.7 for WordPress has SQL injection related to WordPress 4.7.x, a different vulnerability than CVE-201
- Critical 9.8
CVE-2016-10917unauthenticated
The search-everything plugin before 8.1.6 for WordPress has SQL injection related to empty search strings, a different vulnerability than CV
- High 7.5
SQL injection vulnerability in se_search_default in the Search Everything plugin before 7.0.3 for WordPress allows remote attackers to execu
- Medium 6.8
Cross-site request forgery (CSRF) vulnerability in the Search Everything plugin before 8.1.1 for WordPress allows remote attackers to hijack
The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).