Reflected Cross-Site Scripting in Ivory Search Plugin for WordPress
CVE-2026-92243
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 October 2026
What is CVE-2026-92243?
A vulnerability exists in the Ivory Search plugin for WordPress that allows unauthenticated attackers to exploit reflected cross-site scripting via the 's' parameter. This issue arises from insufficient input sanitization and output escaping in all versions up to and including 5.5.18. If an administrator has enabled the 'Highlight Search Terms' option, attackers can craft malicious search queries that may return legitimate post results, leading to arbitrary web scripts being executed in the context of users who access the manipulated search results.
Affected Version(s)
Ivory Search β WordPress Search Plugin 0 <= 5.5.18