BUKAZU Search Widget Plugin Vulnerability

MEDIUM (6.4) No Patch (2 days)

Threat Intelligence

Low Risk
EPSS Score: 0.03% chance of exploitation (percentile: 7%)
🔍 Detection Tools: None available in major open-source tools
⚔️ Exploit Availability: No public exploits found

How we test →

What is it?

The BUKAZU Search widget plugin is a WordPress plugin used for search functionality. This vulnerability allows attackers to inject arbitrary web scripts into pages that will execute when accessed by users with Contributor-level access and above, due to insufficient input sanitization and output escaping on user-supplied attributes.

Am I affected?

You're affected if you use BUKAZU Search widget. Specific version info not stated in the advisory.

Affected Products

WordPress / BUKAZU Search widget plugin

How to fix

To fix the vulnerability, update to BUKAZU Search widget plugin version 3.3.2 or later. If you can't upgrade immediately:

  1. Immediately restrict network access to your WordPress installation (firewall it from the public internet).
  2. Audit admin account activity for suspicious access patterns.
  3. Monitor for unauthorized token creation.

You can download the patched version from the official WordPress plugin repository: https://plugins.trac.wordpress.org/browser/bukazu-search-widget/tags/3.3.2/