CVE · Medium

CVE-2024-6835 — Ivory Search – WordPress Search Plugin [add-search-to-menu] < 5.5.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-6835 Ivory Search – WordPress Search Plugin [add-search-to-menu] < 5.5.7 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.3 < 5.5.7 5.5.7 2024-09-04

CVE-2024-6835

The Ivory Search plugin for WordPress contains a security flaw that allows unauthorized individuals to access sensitive information within password-protected blog entries through a specific vulnerability in its search functionality. This issue arises when the ajax_load_posts function is exploited, enabling attackers to extract text from restricted posts without needing authentication credentials. The problem affects all versions of the plugin up to and including 5.5.6.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.