MEDIUM
vinod-dalvi
CVE published 2026-10-03
CVE-2026-92243
The Ivory Search – WordPress Search Plugin is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 5.5.18. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. However, exploitation requires that the targeted search form has the 'Highlight Search Terms' o [truncated]