Description
WordPress Plugin Ajax Search Pro is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently insert a new user with administrative privileges. WordPress Plugin Ajax Search Pro version 3.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.0 or latest
References
http://research.evex.pw/?vuln=9
http://packetstormsecurity.com/files/130955/WordPress-Ajax-Search-Pro-Remote-Code-Execution.html