WordPress security by component
Ivory Search – WordPress Search Plugin
Plugin description
Ivory Search – WordPress Search Plugin is a WordPress component with 5 published CVE records in this archive. The latest tracked vulnerability was published Jun 27, 2026; the highest CVE/CNA score is 5.3.
Plugin slug:
add-search-to-menuLatest vulnerability
CVE-2026-11356: Ivory Search – WordPress Search Plugin: Cross-site scripting
Ivory Search – WordPress Search Plugin is affected by cross-site scripting. Exploitation requires at least administrator-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 5.5.15.
| Safe version |
|
||
|---|---|---|---|
| Jun 27, 2026 |
CVE-2026-11356
Ivory Search – WordPress Search Plugin: Cross-site scripting
Ivory Search – WordPress Search Plugin is affected by cross-site scripting. Exploitation requires at least administrator-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 5.5.15.
|
> 5.5.15 |
CVE4.4
NVDPending
|
| Jan 28, 2026 |
CVE-2026-1053
Ivory Search – WordPress Search Plugin: Cross-site scripting
Ivory Search – WordPress Search Plugin is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.4
NVDPending
|
| Dec 09, 2025 |
CVE-2025-63069
Ivory Search: A security weakness
Ivory Search is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Sep 05, 2024 |
CVE-2024-6835
Ivory Search – WordPress Search Plugin: A security weakness
Ivory Search – WordPress Search Plugin is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Oct 21, 2021 |
CVE-2021-36869
Add Search To Menu: Cross-site scripting
Add Search To Menu is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVD6.1
|