天下漏洞,尽知其名
MEDIUM

CVE-2026-92243 Ivory Search 反射型跨站脚本漏洞

影响未授权攻击者可注入并执行任意网页脚本

AI 研判

Ivory Search 是 WordPress 的搜索插件,其 's' 参数因输入过滤与输出转义不足,存在反射型跨站脚本漏洞。攻击者可构造恶意搜索链接,诱导用户访问后在其浏览器中执行任意脚本。

影响范围

Ivory Search

影响 Ivory Search 5.5.18 及之前的所有版本。

漏洞详情

漏洞类型为反射型 XSS,成因是插件对搜索参数 's' 未做充分的输入清理和输出转义。攻击者将恶意脚本嵌入搜索查询中,当页面回显该查询时脚本被执行。利用需管理员已启用 'Highlight Search Terms' 选项,且恶意查询需至少返回一条文章结果。

利用条件与风险

利用前提是目标搜索表单启用了高亮搜索词功能且查询能返回结果,无需认证即可投递恶意链接,可窃取会话或进行钓鱼,实战风险中等。

修复建议

建议升级至 5.5.18 之后的修复版本;暂无公开信息时,可临时禁用 'Highlight Search Terms' 选项或对搜索参数进行过滤转义。

原始情报

The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s’ parameter in all versions up to, and including, 5.5.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires that the targeted search form has the ‘Highlight Search Terms’ option enabled by an administrator, and that the malicious search query returns at least one post result.