The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.5.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
We have discovered 33,637 live websites that are affected by CVE-2026-1053.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 33,637 live websites (100% of Ivory Search install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 56 versions ( 100% of all versions) |
| 11,354 websites | |
| 3,132 websites | |
| 1,814 websites | |
| 1,648 websites | |
| 1,369 websites | |
| 992 websites | |
| 930 websites | |
| 872 websites | |
| 870 websites | |
| 773 websites |
| .com | 13,059 websites |
| .org | 2,880 websites |
| .de | 1,810 websites |
| .it | 985 websites |
| .nl | 867 websites |
| .co.uk | 856 websites |
| .fr | 849 websites |
| .net | 714 websites |
| .com.br | 589 websites |
| .pl | 564 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***************.net | *** | ||
| ********.com | *,*** | ||
| *******.uk | *,*** | ||
| **********.com | *,*** | ||
| *********.com | *,*** | ||
| ******.com | *,*** | ||
| ************.com | **,*** | ||
| ***********.org | **,*** | ||
| ************.com | **,*** | ||
| ************.vn | **,*** |
FAQ