CVE-2021-24234: Ivory Search < 4.6.1 - Reflected Cross Site Scripting (XSS)
The Search Forms page of the Ivory Search WordPress lugin before 4.6.1 did not properly sanitise the tab parameter before output it in the page, leading to a reflected Cross-Site Scripting issue when opening a malicious crafted link as a high privilege user. Knowledge of a form id is required to conduct the attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24234?
CVE-2021-24234 is classified as a high severity vulnerability due to its potential for reflected Cross-Site Scripting exploits.
How do I fix CVE-2021-24234?
To fix CVE-2021-24234, update the Ivory Search plugin to version 4.6.1 or later.
Who is affected by CVE-2021-24234?
CVE-2021-24234 affects users of the Ivory Search WordPress plugin versions prior to 4.6.1.
What type of vulnerability is CVE-2021-24234?
CVE-2021-24234 is a reflected Cross-Site Scripting vulnerability.
What must be known to exploit CVE-2021-24234?
To exploit CVE-2021-24234, an attacker must know a valid form ID used in the Ivory Search plugin.