Ivorysearch
Ivorysearch Ivory Search: vulnerabilities and CVEs
Ivorysearch Ivory Search has 10 published vulnerabilities, 4 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs10
Last 12 months4
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-92243 | Medium (6.1) | 0.21% | — | Oct 3, 2026 | The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 5.5.18 due to insufficient input sanitization… |
| CVE-2026-11356 | Medium (4.4) | 0.40% | — | Jun 27, 2026 | The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'menu_title' and 'menu_magnifier_color' Settings in all versions up to, and including, 5.5.15 due to… |
| CVE-2026-1053 | Medium (4.4) | 0.29% | — | Jan 28, 2026 | The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.5.13 due to insufficient input sanitization and… |
| CVE-2025-63069 | Medium (5.3) | 0.32% | — | Dec 9, 2025 | Missing Authorization vulnerability in Vinod Dalvi Ivory Search add-search-to-menu allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ivory Search: from n/a through <= 5.5.12. |
| CVE-2025-5209 | Medium (4.8) | 0.26% | — | Jun 17, 2025 | The Ivory Search WordPress plugin before 5.5.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html… |
| CVE-2024-6835 | Medium (5.3) | 0.52% | — | Sep 5, 2024 | The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 5.5.6 via the ajax_load_posts function. This makes it possible for… |
| CVE-2024-3233 | Medium (4.3) | 0.45% | — | May 2, 2024 | The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_create_index() function in all versions up to, and… |
| CVE-2021-25105 | Medium (4.8) | 0.60% | — | Feb 7, 2022 | The Ivory Search WordPress plugin before 5.4.1 does not escape some of the Form settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is… |
| CVE-2021-36869 | Medium (6.1) | 0.76% | — | Oct 21, 2021 | Reflected Cross-Site Scripting (XSS) vulnerability in WordPress Ivory Search plugin (versions <= 4.6.6). Vulnerable parameter: &post. |
| CVE-2021-24234 | Medium (6.1) | 1.2% | — | Apr 22, 2021 | The Search Forms page of the Ivory Search WordPress lugin before 4.6.1 did not properly sanitise the tab parameter before output it in the page, leading to a reflected Cross-Site Scripting issue when opening a malicious… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.