Cross-Site Scripting Vulnerability in Search in Place Plugin by Codepeople
CVE-2026-95598
7.1HIGH
What is CVE-2026-95598?
A Cross-Site Scripting (XSS) vulnerability exists in the Search in Place plugin by Codepeople that allows attackers to inject malicious scripts. This reflected XSS issue affects versions from n/a up to 1.5.5, enabling unauthorized actions executed on behalf of the user. If exploited, this vulnerability could compromise user data and site integrity, making it crucial for website owners to ensure their plugins are up-to-date and secure.
Affected Version(s)
Search in Place 0 <= 1.5.5