# WP Search with Algolia <= 2.14.1 - Authenticated (Subscriber+) Missing Authorization to Index Re-Indexing and Settings Push

- **ID:** WPSEC-2026-0640
- **Plugin:** WP Search with Algolia (`wp-search-with-algolia`), https://wordpress.org/plugins/wp-search-with-algolia/
- **Affected versions:** all versions before 3.0.0
- **Fixed in:** 3.0.0 (Update to 3.0.0 or later.)
- **Severity:** Medium 5.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L)
- **Weakness:** CWE-862
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-08)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/wp-search-with-algolia
- **Fix released:** 2026-10-07
- **Published:** 2026-10-08
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0640/

## Description

The WP Search with Algolia plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce validation on the 'algolia_re_index' and 'algolia_push_settings' AJAX actions in all versions up to, and including, 2.14.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to re-index any of the plugin's Algolia indices. Re-indexing an existing index from the first page clears it and refills only the first batch of records, which can leave site search returning incomplete results until an administrator runs a full re-index. Attackers can also create and populate indices that the administrator has not chosen to index (published, non-password-protected content only) and push the plugin's index settings, synonyms and replica configuration to Algolia, overriding changes made in the Algolia dashboard.

## References

- https://wpsec.com/vuln/WPSEC-2026-0640/
- https://plugins.svn.wordpress.org/wp-search-with-algolia/tags/3.0.0/
- https://wordpress.org/plugins/wp-search-with-algolia/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0640/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
