Ivorysearch

Ivory Search

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.05%
  • Veröffentlicht 17.06.2025 06:00:04
  • Zuletzt bearbeitet 26.06.2025 16:01:40

The Ivory Search WordPress plugin before 5.5.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

  • EPSS 0.93%
  • Veröffentlicht 05.09.2024 07:15:02
  • Zuletzt bearbeitet 11.09.2024 16:32:16

The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 5.5.6 via the ajax_load_posts function. This makes it possible for unauthenticated attackers to extract text d...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 07.02.2022 16:15:45
  • Zuletzt bearbeitet 21.11.2024 05:54:21

The Ivory Search WordPress plugin before 5.4.1 does not escape some of the Form settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

  • EPSS 0.22%
  • Veröffentlicht 21.10.2021 21:15:07
  • Zuletzt bearbeitet 21.11.2024 06:14:13

Reflected Cross-Site Scripting (XSS) vulnerability in WordPress Ivory Search plugin (versions <= 4.6.6). Vulnerable parameter: &post.

Exploit
  • EPSS 0.27%
  • Veröffentlicht 22.04.2021 21:15:09
  • Zuletzt bearbeitet 21.11.2024 05:52:39

The Search Forms page of the Ivory Search WordPress lugin before 4.6.1 did not properly sanitise the tab parameter before output it in the page, leading to a reflected Cross-Site Scripting issue when opening a malicious crafted link as a high privile...