Description
The XiSearch bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6. This is due to missing or incorrect nonce validation on the 'xisearch-key-config' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Published: 2025-06-14
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting enabled by CSRF
Action: Patch Immediately
AI Analysis

Impact

The vulnerability stems from improper nonce validation on the configuration page of the XiSearch bar WordPress plugin, allowing a forged request to alter settings. An attacker can inject malicious JavaScript that will be persisted in the site’s configuration, leading to stored cross‑site scripting on subsequent page loads. This gives the attacker the ability to execute arbitrary scripts in the context of any visitor, potentially compromising session data, defacing content, or facilitating further attacks.

Affected Systems

All installations of the XiSearch bar plugin for WordPress with versions 2.6 and earlier are affected. No specific build numbers exist beyond the "<=2.6" threshold, so any site running a non‑updated instance of this plugin is vulnerable.

Risk and Exploitability

The CVSS score of 6.1 indicates a moderate severity. With an EPSS score of less than 1%, exploitation is unlikely but logically feasible; the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is an unauthenticated CSRF request that convinces an administrator to click a crafted link, triggering the non‑validated request and inserting the malicious script.

Generated by OpenCVE AI on April 20, 2026 at 22:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the XiSearch bar plugin to a version newer than 2.6 to obtain the nonce validation fix
  • If an update is unavailable, remove or disable the XiSearch bar plugin until a secure version is released
  • Ensure the WordPress installation, core and all other plugins are up to date and consider implementing additional application whitelisting or configuration file integrity monitoring to detect unauthorized changes

Generated by OpenCVE AI on April 20, 2026 at 22:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-18322 The XiSearch bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6. This is due to missing or incorrect nonce validation on the 'xisearch-key-config' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
History

Fri, 27 Feb 2026 00:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00013}

epss

{'score': 0.00015}


Sat, 14 Jun 2025 08:45:00 +0000

Type Values Removed Values Added
Description The XiSearch bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6. This is due to missing or incorrect nonce validation on the 'xisearch-key-config' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Title XiSearch bar <= 2.6 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:24:09.721Z

Reserved: 2025-06-13T13:27:55.518Z

Link: CVE-2025-6063

cve-icon Vulnrichment

Updated: 2025-06-16T16:47:08.350Z

cve-icon NVD

Status : Deferred

Published: 2025-06-14T09:15:24.693

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-6063

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-20T22:45:20Z

Weaknesses