Vulnerabilities > Ivorysearch

DATE CVE VULNERABILITY TITLE RISK
2024-09-05 CVE-2024-6835 Unspecified vulnerability in Ivorysearch Ivory Search
The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 5.5.6 via the ajax_load_posts function.
network
low complexity
ivorysearch
5.3
2022-02-07 CVE-2021-25105 Cross-site Scripting vulnerability in Ivorysearch Ivory Search
The Ivory Search WordPress plugin before 5.4.1 does not escape some of the Form settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
network
low complexity
ivorysearch CWE-79
4.8
2021-10-21 CVE-2021-36869 Cross-site Scripting vulnerability in Ivorysearch Ivory Search
Reflected Cross-Site Scripting (XSS) vulnerability in WordPress Ivory Search plugin (versions <= 4.6.6).
network
low complexity
ivorysearch CWE-79
6.1
2021-04-22 CVE-2021-24234 Unspecified vulnerability in Ivorysearch Ivory Search
The Search Forms page of the Ivory Search WordPress lugin before 4.6.1 did not properly sanitise the tab parameter before output it in the page, leading to a reflected Cross-Site Scripting issue when opening a malicious crafted link as a high privilege user.
network
low complexity
ivorysearch
6.1