Impact
The plugin accepts the search query the 's' parameter and outputs the search terms in highlighted HTML without proper sanitization. This flaw enables an attacker to inject scripts that run in any user’s browser when the processed page loads. The risk is that malicious code can execute with the privileges of the browsing user, allowing cookie theft, session hijacking, or defacement.
Affected Systems
The vulnerability affects the Ivory Search – WordPress Search Plugin in versions 5.5.18 and earlier. System administrators who have installed any of those versions on a WordPress site may be exposed.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate severity. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the flaw by sending a crafted search query to a public search form that has the 'Highlight Search Terms' feature enabled and that returns at least one post. The attack requires no authentication and works by simply accessing a URL containing the malicious payload.
OpenCVE Enrichment