CVE-2024-13362
Ivory Search – WordPress Search Plugin
Minimum safe version
5.5.14
Update to 5.5.14 or later to address 23 fixable vulnerabilities
Ivory Search <= 5.5.13 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'menu_gcse' and 'nothing_found_text' Parameters
CVE-2025-63069
WordPress Ivory Search Plugin < 5.5.10 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2024-6835
CVE-2024-3233
WordPress Ivory Search Plugin < 5.5.2 is vulnerable to Cross Site Scripting (XSS)
Ivory Search – WordPress Search Plugin <= 4.5.10 - Reflected Cross-Site Scripting
Ivory Search <= 4.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Freemius SDK <= 2.4.2 - Missing Authorization Checks
Ivory Search <= 5.4.6 - Reflected Cross-Site Scripting
Ivory Search < 4.5.11 - Authenticated Reflected Cross-Site Scripting (XSS)
Ivory Search < 4.8 - Contributor+ Stored Cross-Site Scripting
Ivory Search < 5.4.7 - Reflected Cross-Site Scripting
WordPress Ivory Search plugin <= 5.4.6 - Reflected Cross-Site Scripting (XSS) vulnerability
WordPress Ivory Search plugin <= 4.5.10 - Cross-Site Scripting (XSS) vulnerability
WordPress Ivory Search plugin <= 4.7 - Authenticated Persistent Cross-Site Scripting (XSS) vulnerability
WordPress Ivory Search plugin < 5.4.4 - Sensitive Information Disclosure vulnerability
WordPress Ivory Search plugin < 5.4.4 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability
CVE-2021-24234
CVE-2021-36869
CVE-2021-25105