cleantalk
Vulnerabilities and Security Researches

Ivory Search – WordPress Search Plugin, 0a3d23ba799ad9e23da88ec8ee4c14432acb79fc

Published on
Nov 02, 2021
Research Description
Ivory Search &#8211; WordPress Search Plugin [add-search-to-menu] < 4.8 Ivory Search <= 4.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting The Ivory Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in versions up to, and including, 4.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated Contributor+ attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 4.8.
Status
vulnerable