PT-2025-39765 · Quadlayers · Search Exclude

Lucas Montes

·

Published

2025-09-28

·

Updated

2025-11-25

·

CVE-2025-10646

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WordPress Search Exclude plugin versions up to and including 2.5.7
Description The WordPress Search Exclude plugin contains a flaw that allows unauthorized modification of data. This is due to an inadequate capability check within the Base::get rest permission() method. Authenticated attackers possessing Contributor-level access or higher can alter plugin settings, specifically adding arbitrary posts to the search exclusion list.
Recommendations Update the WordPress Search Exclude plugin to a version later than 2.5.7.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-10646

Affected Products

Search Exclude