Junglewise Threat Intelligence

CVE-2026-11356: Ivory Search WordPress Plugin Stored XSS in Settings

CVE-2026-11356 · Severity: medium · CVSS 4.4 · Published 2026-06-27

Executive brief

Ivory Search is a WordPress plugin used to enhance website search functionality. A security vulnerability allows an attacker with administrative access to save malicious scripts into the plugin's settings. These scripts will then run automatically in the browser of any user who visits the affected pages, potentially leading to unauthorized actions or data theft.

Technical details

The Ivory Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'menu_title' and 'menu_magnifier_color' settings. An authenticated attacker with administrator-level privileges can inject arbitrary web scripts into these fields. Because the plugin fails to properly clean this data before storing it and displaying it back to users, the scripts will execute in the context of any user's browser session when they access the modified pages. This vulnerability affects all versions up to and including 5.5.15. A patch is available in newer versions.

Affected products

  • vinod-dalvi Ivory Search – WordPress Search Plugin up to, and including, 5.5.15

Timeline

  • 2026-06-27: disclosed
  • 2026-06-27: advisory

References