WP Search with Algolia <= 2.14.1 - Authenticated (Subscriber+) Missing Authorization to Index Re-Indexing and Settings Push

Medium 5.4 CWE-862Fixed in 3.0.0
ID
WPSEC-2026-0640
Plugin
WP Search with Algolia (wp-search-with-algolia)
Affected
all versions before 3.0.0
Remediation
Update to 3.0.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Weakness
CWE-862
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-08
Attack surface
WP Search with Algolia on WPSec AttackSurface
Fix released
Published

Description

The WP Search with Algolia plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce validation on the 'algolia_re_index' and 'algolia_push_settings' AJAX actions in all versions up to, and including, 2.14.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to re-index any of the plugin's Algolia indices. Re-indexing an existing index from the first page clears it and refills only the first batch of records, which can leave site search returning incomplete results until an administrator runs a full re-index. Attackers can also create and populate indices that the administrator has not chosen to index (published, non-password-protected content only) and push the plugin's index settings, synonyms and replica configuration to Algolia, overriding changes made in the Algolia dashboard.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0