CVE-2025-30894

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Mar 27, 2025
CWE ID 862

Summary

CVE-2025-30894 is a Missing Authorization vulnerability affecting WP Fast Total Search, a popular search plugin for WordPress. The flaw allows unauthorized access to data due to incorrectly configured access control security levels. This issue can be exploited by adversaries to gain unauthorized access to information, potentially leading to data breaches. WP Fast Total Search versions from n/a to 1.79.262 are susceptible to this vulnerability. Users are strongly advised to update their plugins to the latest version and implement strong access controls to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share