rootpwn

medium · CVSS v3 6.1

CVE-2026-92243

The Ivory Search – WordPress Search Plugin is vulnerable to reflected XSS via the 's' parameter in all versions up to 5.5.18. Unauthenticate

Overview

The Ivory Search – WordPress Search Plugin is vulnerable to reflected XSS via the 's' parameter in all versions up to 5.5.18. Unauthenticated attackers can inject scripts that execute when a user views a search result page. This flaw requires the admin to enable 'Highlight Search Terms' and a search query that returns a post.

Description

The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 5.5.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires that the targeted search form has the 'Highlight Search Terms' option enabled by an administrator, and that the malicious search query returns at least one post result.

Impact

The vulnerability allows attackers to run arbitrary JavaScript in the context of the site, potentially stealing user cookies, hijacking sessions, or delivering phishing content. Site visitors and administrators are at risk of credential theft, defacement, or malicious redirects. Defenders should be aware that any user who views a crafted search result could be compromised.

Remediation

Update the Ivory Search plugin to the latest version (5.5.19 or newer) where input sanitization and output escaping have been fixed. If an update is not immediately possible, disable the 'Highlight Search Terms' feature in the plugin settings to eliminate the reflected XSS vector. Additionally, ensure the WordPress core and all other plugins are kept up to date and consider implementing a web application firewall that blocks suspicious query strings.

Risk context

The CVSS v3 score of 6.1 indicates medium severity. With no EPSS data available, the risk remains moderate; defenders should prioritize patching or mitigation to prevent potential exploitation.

Affected products

  • Ivory Search plugin for WordPress
  • WordPress Search Plugin
  • WordPress
  • Ivory Search 5.5.18
  • WordPress plugin
  • WordPress 5.5.18
  • WordPress 5.5.18 plugin

Scores

Severity
medium
CVSS v2
6.4
CVSS v3
6.1
CVSS v4
—
EPSS
—

XSS WordPress Ivory Search Reflected XSS Web Vulnerability Search Plugin Medium Severity

← All CVEs