Cross-site Scripting Vulnerability in CodeManas Search with Typesense
CVE-2025-49304
6.5MEDIUM
What is CVE-2025-49304?
The CodeManas Search with Typesense plugin for WordPress is susceptible to a Cross-site Scripting (XSS) vulnerability, allowing attackers to inject malicious scripts via user input. This can lead to the execution of arbitrary JavaScript in the context of authenticated users, potentially compromising sensitive information or hijacking user sessions. The vulnerability affects versions from n/a to 2.0.10.
Affected Version(s)
Search with Typesense <= 2.0.10