Description
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.16. This is due to missing or incorrect nonce validation on the `process_bulk_action()` function of `MWTSA_Stats_Table`. This makes it possible for unauthenticated attackers to delete arbitrary search-term records, including all associated search-history rows, via a forged request granted they can trick a user with access to the plugin's "Search Analytics" dashboard page (Administrator by default) into performing an action such as clicking on a link.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 05 Aug 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cornelraiu
Cornelraiu wp Search Analytics Wordpress Wordpress wordpress |
|
| Vendors & Products |
Cornelraiu
Cornelraiu wp Search Analytics Wordpress Wordpress wordpress |
Wed, 05 Aug 2026 07:30:00 +0000
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-08-05T06:38:01.030Z
Reserved: 2026-04-29T16:49:36.441Z
Link: CVE-2026-7444
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-05T09:30:11Z
Weaknesses