CVE-2026-96352: WordPress YITH WooCommerce Ajax Search plugin <= 2.28.0 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in YITH WooCommerce Ajax Search <= 2.28.0 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress YITH WooCommerce Ajax Search pluginto a version that resolves this vulnerability.Fixed in 2.28.1
Event History
Frequently Asked Questions
Who can exploit this issue?
The issue is unauthenticated, so an attacker does not need a WordPress account or plugin-level privileges. Exploitation requires user interaction, as indicated by the UI:R vector.
What impact could successful exploitation have?
The supplied CVSS vector indicates low confidentiality, integrity, and availability impact, with scope changed. The vulnerability is network-accessible and has low attack complexity.
Which plugin versions should be treated as affected?
YITH WooCommerce Ajax Search versions 2.28.0 and earlier are identified as affected. The provided data does not identify a fixed version.