What is CVE-2026-12741?
This vulnerability in the 'WP Fast Total Search – The Power of Indexed Search' WordPress plugin allows SQL Injection via the 'form_data[s]' parameter due to insufficient escaping. Users should update the plugin to the latest patched version or temporarily disable it until a fix is applied.
Azərbaycanca: Bu zəiflik WordPress-in 'WP Fast Total Search – The Power of Indexed Search' plaginində SQL Injection hücumuna imkan verir. 'form_data[s]' parametri üzərindən təhlükəli sorğular göndərmək mümkündür. İstifadəçilər plagini ən son təhlükəsizlik yeniləməsinə qədər yeniləməli və ya müvəqqəti olaraq deaktiv etməlidirlər.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
In which WordPress plugin was CVE-2026-12741 discovered?
This vulnerability was discovered in the 'WP Fast Total Search – The Power of Indexed Search' plugin.
What should users do to protect against CVE-2026-12741?
Users should update the plugin to the latest patched version or temporarily disable it until a fix is applied.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.