Description
The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 5.5.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires that the targeted search form has the 'Highlight Search Terms' option enabled by an administrator, and that the malicious search query returns at least one post result.
Published: 2026-10-03
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting via reflected DOM‑Based parameter leading to arbitrary script execution in browsers
Action: Patch Immediately
AI Analysis

Impact

The plugin accepts the search query the 's' parameter and outputs the search terms in highlighted HTML without proper sanitization. This flaw enables an attacker to inject scripts that run in any user’s browser when the processed page loads. The risk is that malicious code can execute with the privileges of the browsing user, allowing cookie theft, session hijacking, or defacement.

Affected Systems

The vulnerability affects the Ivory Search – WordPress Search Plugin in versions 5.5.18 and earlier. System administrators who have installed any of those versions on a WordPress site may be exposed.

Risk and Exploitability

The CVSS score of 6.1 indicates a moderate severity. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the flaw by sending a crafted search query to a public search form that has the 'Highlight Search Terms' feature enabled and that returns at least one post. The attack requires no authentication and works by simply accessing a URL containing the malicious payload.

Generated by OpenCVE AI on October 3, 2026 at 03:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Ivory Search plugin to version 5.5.19 or later
  • If an update is not possible, disable the 'Highlight Search Terms' option in the plugin settings to eliminate the vector
  • If neither update nor disabling the option is feasible, remove or deactivate the Ivory Search plugin entirely

Generated by OpenCVE AI on October 3, 2026 at 03:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 02:45:00 +0000

Type Values Removed Values Added
Description The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 5.5.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires that the targeted search form has the 'Highlight Search Terms' option enabled by an administrator, and that the malicious search query returns at least one post result.
Title Ivory Search <= 5.5.18 - Reflected DOM-Based Cross-Site Scripting via 's' Parameter
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:47.046Z

Reserved: 2026-09-15T20:10:29.826Z

Link: CVE-2026-92243

cve-icon Vulnrichment

Updated: 2026-10-03T15:39:46.223Z

cve-icon NVD

Status : Received

Published: 2026-10-03T03:16:36.910

Modified: 2026-10-03T16:16:41.830

Link: CVE-2026-92243

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T03:30:19Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')