Plugin Vulnerability Hub
Plugin 11 known issues Latest disclosed Jan 27, 2026

Ivory Search – WordPress Search Plugin Vulnerabilities

Review known vulnerability records for the WordPress plugin Ivory Search – WordPress Search Plugin (`add-search-to-menu`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-1053, CVE-2025-63069 and CVE-2025-5209, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
11
High or Critical
0
Patch Coverage
100%
Last Updated
Jan 28, 2026
Priority CVE Quick Links

Fast paths into Ivory Search – WordPress Search Plugin CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
8
CVE-2021-36869 Medium 4.7
CVE-2021-36869 Ivory Search – WordPress Search Plugin Cross-Site Scripting

Ivory Search <= 4.6.6 - Reflected Cross-Site Scripting

CVE-2021-24234 Medium 4.6.1
CVE-2021-24234 Ivory Search – WordPress Search Plugin Cross-Site Scripting

Ivory Search <= 4.6 - Reflected Cross Site Scripting

CVE-2025-63069 Medium 5.5.13
CVE-2025-63069 Ivory Search – WordPress Search Plugin Vulnerability

Ivory Search <= 5.5.12 - Missing Authorization

CVE-2024-6835 Medium 5.5.7
CVE-2024-6835 Ivory Search – WordPress Search Plugin Vulnerability

Ivory Search – WordPress Search Plugin <= 5.5.6 - Information Exposure via AJAX Search Form

CVE-2021-25105 Medium 5.4.1
CVE-2021-25105 Ivory Search – WordPress Search Plugin Stored Cross-Site Scripting

Ivory Search <= 5.4 - Multiple Admin+ Stored Cross-Site Scripting

CVE-2026-1053 Medium 5.5.14
CVE-2026-1053 Ivory Search – WordPress Search Plugin Stored Cross-Site Scripting

Ivory Search <= 5.5.13 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'menu_gcse' and 'nothing_found_text' Parameters

CVE-2025-5209 Medium 5.5.10
CVE-2025-5209 Ivory Search – WordPress Search Plugin Stored Cross-Site Scripting

Ivory Search – WordPress Search Plugin <= 5.5.9 - Authenticated (Admin+) Stored Cross-Site Scripting

CVE-2024-3233 Medium 5.5.6
CVE-2024-3233 Ivory Search – WordPress Search Plugin Vulnerability

Ivory Search – WordPress Search Plugin <= 5.5.5 - Missing Authorization to Authenticated (Subscriber+) Index Creation

Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Ivory Search – WordPress Search Plugin so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
11 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
0 critical and 0 high severity findings.
Recent CVEs
CVE-2026-1053, CVE-2025-63069 and CVE-2025-5209
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for Ivory Search – WordPress Search Plugin

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2026-1053
CVE-2026-1053: Ivory Search <= 5.5.13 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'menu_gcse' and 'nothing_found_text' Parameters

The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.5.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack...

Published
Jan 27, 2026
Patched Release
5.5.14
Affected Versions
Versions up to 5.5.13
Next Step
Update to 5.5.14 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-63069
CVE-2025-63069: Ivory Search <= 5.5.12 - Missing Authorization

The Ivory Search plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.5.12. This makes it possible for unauthenticated attackers to perform an unauthorized action.

Published
Sep 28, 2025
Patched Release
5.5.13
Affected Versions
Versions up to 5.5.12
Next Step
Update to 5.5.13 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-5209
CVE-2025-5209: Ivory Search – WordPress Search Plugin <= 5.5.9 - Authenticated (Admin+) Stored Cross-Site Scripting

The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.5.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attacke...

Published
May 27, 2025
Patched Release
5.5.10
Affected Versions
Versions up to 5.5.9
Next Step
Update to 5.5.10 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-6835
CVE-2024-6835: Ivory Search – WordPress Search Plugin <= 5.5.6 - Information Exposure via AJAX Search Form

The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 5.5.6 via the ajax_load_posts function. This makes it possible for unauthenticated attackers to extract text data from password-protected po...

Published
Sep 04, 2024
Patched Release
5.5.7
Affected Versions
Versions up to 5.5.6
Next Step
Update to 5.5.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-3233
CVE-2024-3233: Ivory Search – WordPress Search Plugin <= 5.5.5 - Missing Authorization to Authenticated (Subscriber+) Index Creation

The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_create_index() function in all versions up to, and including, 5.5.5. This makes it possible for authenticated attackers...

Published
Apr 12, 2024
Patched Release
5.5.6
Affected Versions
Versions up to 5.5.5
Next Step
Update to 5.5.6 or newer if supported.
Plugin Medium Patched: Yes
Ivory Search <= 5.4.6 - Reflected Cross-Site Scripting

The Ivory Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in versions up to, and including, 5.4.6 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts...

Published
Jul 04, 2022
Patched Release
5.4.7
Affected Versions
Versions up to 5.4.6
Next Step
Update to 5.4.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2021-25105
CVE-2021-25105: Ivory Search <= 5.4 - Multiple Admin+ Stored Cross-Site Scripting

The Ivory Search WordPress plugin before 5.4.1 does not escape some of the Form settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

Published
Jan 10, 2022
Patched Release
5.4.1
Affected Versions
Versions up to 5.4
Next Step
Update to 5.4.1 or newer if supported.
Plugin Medium Patched: Yes
Ivory Search <= 4.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Ivory Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in versions up to, and including, 4.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated Contributor+ attackers to inject...

Published
Nov 02, 2021
Patched Release
4.8
Affected Versions
Versions up to 4.7.1
Next Step
Update to 4.8 or newer if supported.
Plugin Medium Patched: Yes CVE-2021-36869
CVE-2021-36869: Ivory Search <= 4.6.6 - Reflected Cross-Site Scripting

Reflected Cross-Site Scripting (XSS) vulnerability in WordPress Ivory Search plugin (versions

Published
Oct 01, 2021
Patched Release
4.7
Affected Versions
Versions up to 4.6.6
Next Step
Update to 4.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2021-24234
CVE-2021-24234: Ivory Search <= 4.6 - Reflected Cross Site Scripting

The Search Forms page of the Ivory Search WordPress lugin before 4.6.1 did not properly sanitise the tab parameter before output it in the page, leading to a reflected Cross-Site Scripting issue when opening a malicious crafted link as a high privilege user. Knowledge of a form i...

Published
Mar 30, 2021
Patched Release
4.6.1
Affected Versions
Versions up to 4.6
Next Step
Update to 4.6.1 or newer if supported.
Plugin Medium Patched: Yes
Ivory Search – WordPress Search Plugin <= 4.5.10 - Reflected Cross-Site Scripting

The "Ivory Search – WordPress Search Plugin" plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘post’ parameter in versions up to, and including, 4.5.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated...

Published
Feb 01, 2021
Patched Release
4.5.11
Affected Versions
Versions up to 4.5.10
Next Step
Update to 4.5.11 or newer if supported.