A vulnerability described as critical has been identified in epsiloncool WP Fast Total Search Plugin up to 1.80.280 on WordPress. The impacted element is an unknown function. The manipulation of the argument form_data[s] results in sql injection.

This vulnerability was named CVE-2026-12741. The attack may be performed from remote. There is no available exploit.