Description
WordPress Plugin Search Everything is prone to a cross-site request forgery vulnerability. Exploiting this issue may allow a remote attacker to perform certain administrative actions and gain unauthorized access to the affected application; other attacks are also possible. WordPress Plugin Search Everything version 8.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 8.1.1 or latest
References
Related Vulnerabilities
WordPress Plugin Booking Calendar Contact Form Multiple Vulnerabilities (1.0.2)
PHP Use After Free Vulnerability (CVE-2016-9137)
PHP Use of Externally-Controlled Format String Vulnerability (CVE-2010-2094)
Drupal Core 6.x Multiple Vulnerabilities (6.0 - 6.17)
WordPress Plugin Admin Pack by SITE CASEIRO Cross-Site Scripting (1.1)