WordPress Plugin Sell Media v2.4.1 contains a cross-site scripting vulnerability in /inc/class-search.php that allows remote attackers to inject arbitrary web script or HTML via the keyword parameter (aka $search_term or the Search field).
id: CVE-2019-6112
info:
name: WordPress Sell Media 2.4.1 - Cross-Site Scripting
author: dwisisw
...