CVE-2020-12070: Advanced-Woo-Search Advanced Woo Search

High severity, CVSS 7.5. EPSS: 2% chance of exploitation in the next 30 days.

The Advanced Woo Search plugin version through 1.99 for Wordpress suffers from a sensitive information disclosure vulnerability in every ajax search request via the sql field to includes/class-aws-search.php.

Affected products

Published 2020-04-24. Last modified 2026-06-17.