WP Search with Algolia <= 2.14.1 - Authenticated (Subscriber+) Missing Authorization to Index Re-Indexing and Settings Push
- ID
- WPSEC-2026-0640
- Plugin
- WP Search with Algolia (wp-search-with-algolia)
- Affected
- all versions before 3.0.0
- Remediation
- Update to 3.0.0 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
- Weakness
- CWE-862
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-08
- Attack surface
- WP Search with Algolia on WPSec AttackSurface
- Fix released
- Published
Description
The WP Search with Algolia plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce validation on the 'algolia_re_index' and 'algolia_push_settings' AJAX actions in all versions up to, and including, 2.14.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to re-index any of the plugin's Algolia indices. Re-indexing an existing index from the first page clears it and refills only the first batch of records, which can leave site search returning incomplete results until an administrator runs a full re-index. Attackers can also create and populate indices that the administrator has not chosen to index (published, non-password-protected content only) and push the plugin's index settings, synonyms and replica configuration to Algolia, overriding changes made in the Algolia dashboard.
References
- https://wpsec.com/vuln/WPSEC-2026-0640/
- https://plugins.svn.wordpress.org/wp-search-with-algolia/tags/3.0.0/
- https://wordpress.org/plugins/wp-search-with-algolia/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS