{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/wp-fast-total-search--the-power-of-indexed-search--1.80.280/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-12741"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WP Fast Total Search – The Power of Indexed Search (\u003c= 1.80.280)"],"_cs_severities":["high"],"_cs_tags":["wordpress","plugin","sql-injection","web-vulnerability","data-exfiltration"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eA critical SQL injection vulnerability, tracked as CVE-2026-12741, has been identified in the \u0026quot;WP Fast Total Search - The Power of Indexed Search\u0026quot; WordPress plugin, impacting all versions up to and including 1.80.280. This flaw stems from inadequate sanitization and escaping of user-supplied input, specifically within the \u003ccode\u003eform_data[s]\u003c/code\u003e parameter, and insufficient preparation of existing SQL queries. Exploitation of this vulnerability allows unauthenticated attackers to append arbitrary SQL queries to legitimate database interactions. By leveraging this, attackers can bypass authentication, manipulate database content, or, most notably, extract sensitive information directly from the WordPress database, including user credentials, configuration settings, and other proprietary data. This poses a significant risk to the integrity and confidentiality of websites utilizing the affected plugin.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker identifies a WordPress website running the vulnerable \u0026quot;WP Fast Total Search\u0026quot; plugin.\u003c/li\u003e\n\u003cli\u003eThe attacker constructs a specially crafted HTTP POST request targeting an endpoint that processes search queries from the plugin, typically \u003ccode\u003ewp-admin/admin-ajax.php\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe malicious request includes an SQL injection payload embedded within the \u003ccode\u003eform_data[s]\u003c/code\u003e parameter (e.g., \u003ccode\u003eform_data[s]=searchterm' UNION SELECT user_login,user_pass FROM wp_users--\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe vulnerable plugin receives the request and, due to insufficient input validation and improper SQL query construction, directly incorporates the attacker's payload into the backend database query.\u003c/li\u003e\n\u003cli\u003eThe database management system executes the combined, malicious SQL query.\u003c/li\u003e\n\u003cli\u003eThe database responds to the web server, including the results of the attacker's injected query, such as exfiltrated sensitive data like user credentials.\u003c/li\u003e\n\u003cli\u003eThe web server returns the modified response to the attacker, who then parses the HTTP body to extract the sensitive information.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-12741 grants unauthenticated attackers the ability to extract sensitive information directly from the website's database. This includes, but is not limited to, administrator credentials, user data, plugin configurations, and other proprietary business information. Such data exfiltration can lead to complete website compromise, unauthorized access to user accounts, data breaches, and further malicious activities like defacement or malware injection. The impact on confidentiality and integrity is severe, potentially resulting in reputational damage, regulatory fines, and significant operational disruption for affected organizations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ePatch CVE-2026-12741\u003c/strong\u003e: Immediately update the \u0026quot;WP Fast Total Search - The Power of Indexed Search\u0026quot; WordPress plugin to a patched version beyond 1.80.280 to remediate CVE-2026-12741.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeploy the Sigma rules\u003c/strong\u003e: Deploy the \u003ccode\u003eDetect CVE-2026-12741 Exploitation - WP Fast Total Search SQLi Attempt\u003c/code\u003e Sigma rule to your SIEM to identify and alert on attempted exploitation of CVE-2026-12741.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eEnable webserver logging\u003c/strong\u003e: Ensure comprehensive webserver logging (e.g., Apache, Nginx access logs) is enabled to capture \u003ccode\u003ecs-method\u003c/code\u003e, \u003ccode\u003ecs-uri-stem\u003c/code\u003e, \u003ccode\u003ecs-uri-query\u003c/code\u003e, and \u003ccode\u003esc-status\u003c/code\u003e for full visibility into HTTP requests.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-28T08:20:30Z","date_published":"2026-07-28T08:20:30Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-12741-wp-fast-total-search-sqli/","summary":"An SQL injection vulnerability (CVE-2026-12741) exists in the WP Fast Total Search - The Power of Indexed Search plugin for WordPress, affecting all versions up to and including 1.80.280. The flaw, located in the 'form_data[s]' parameter, is due to insufficient input escaping and poor SQL query preparation, allowing unauthenticated attackers to inject malicious SQL queries and extract sensitive information from the underlying database.","title":"CVE-2026-12741: Unauthenticated SQL Injection in WP Fast Total Search WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-12741-wp-fast-total-search-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - WP Fast Total Search – The Power of Indexed Search (\u003c= 1.80.280)","version":"https://jsonfeed.org/version/1.1"}