Reflected Cross-Site Scripting in Ivory Search Plugin for WordPress
CVE-2026-92243

6.1MEDIUM

What is CVE-2026-92243?

A vulnerability exists in the Ivory Search plugin for WordPress that allows unauthenticated attackers to exploit reflected cross-site scripting via the 's' parameter. This issue arises from insufficient input sanitization and output escaping in all versions up to and including 5.5.18. If an administrator has enabled the 'Highlight Search Terms' option, attackers can craft malicious search queries that may return legitimate post results, leading to arbitrary web scripts being executed in the context of users who access the manipulated search results.

Affected Version(s)

Ivory Search – WordPress Search Plugin 0 <= 5.5.18

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

@nacento
.