Snyk has a published code exploit for this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsAvoid using smartsearchwp
altogether.
smartsearchwp is a malicious package.
Affected versions of this package are malicious. By traversing DOM elements, looking for fields such as username
and passwords
, the package is intended to steal credentials from a website it is logged in, and uploads it to a remote server.