CVE-2021-36869: WordPress Ivory Search plugin <= 4.6.6 - Reflected Cross-Site Scripting (XSS) vulnerability
Published Oct 21, 2021
·Updated
Reflected Cross-Site Scripting (XSS) vulnerability in WordPress Ivory Search plugin (versions <= 4.6.6). Vulnerable parameter: &post.
Affected Software
1 affected component
Ivorysearch Ivory Search Wordpress<=4.6.6
Remediation
Information
Update to 4.7 or higher version.
Event History
Oct 21, 2021
CVE Published
via MITRE·08:18 PM
Data Sourced
via MITRE·08:18 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-36869?
CVE-2021-36869 has been classified as a medium severity reflected Cross-Site Scripting vulnerability.
2
How do I fix CVE-2021-36869?
To fix CVE-2021-36869, users should upgrade the Ivory Search plugin to version 4.6.7 or later.
3
Which versions of the Ivory Search plugin are affected by CVE-2021-36869?
CVE-2021-36869 affects all versions of the Ivory Search plugin up to and including 4.6.6.
4
What are the potential impacts of exploiting CVE-2021-36869?
Exploiting CVE-2021-36869 may allow attackers to execute arbitrary scripts in a user's browser, potentially compromising user data.
5
Where can I find more information about CVE-2021-36869?
Detailed information about CVE-2021-36869 can typically be found in the security advisories and update logs from Ivory Search.