Ivory Search – WordPress 搜索插件在 5.5.18 及以下所有版本中存在反射型跨站脚本(XSS)漏洞,该漏洞源于对 's' 参数的输入过滤和输出转义不足。攻击者无需认证即可在页面中注入任意 Web 脚本,当用户访问被注入的页面时,这些脚本便会执行。成功利用此漏洞需满足两个条件:一是目标网站的管理员已启用“高亮显示搜索关键词”选项;二是恶意的搜索查询必须至少返回一条文章结果。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| vinod-dalvi | Ivory Search – WordPress Search Plugin | ≤ 5.5.18 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| vinod-dalvi | Ivory Search – WordPress Search Plugin | 0 ~ 5.5.18 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet