Known vulnerabilities in ElasticPress
A fast and flexible search and query engine for WordPress.
5Reported vulnerabilities
9.8Highest CVSS score
5.3.3Latest version
8,000+Active installs
What to do now
Update ElasticPress to 5.1.1 or later.
5 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2022-25912 | Critical | 2.8% | 4.4.0 and earlier | 4.4.1 |
December 5, 2022 |
| WF-0315f5de-7a46-4e16-b080-557ddfd180a2 | High | — | 4.1.0 and earlier | 4.2.0 |
April 5, 2022 |
| CVE-2022-37601 | Medium | 2.8% | 4.3.1 and earlier | 4.4.0 |
October 12, 2022 |
| CVE-2024-35684 | Medium | 0.2% | 5.1.0 and earlier | 5.1.1 |
June 6, 2024 |
| CVE-2021-4405 | Medium | 0.4% | 3.5.3 and earlier | 3.5.4 |
July 1, 2023 |