Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Better Search better-search allows Stored XSS.This issue affects Better Search: from n/a through <= 4.2.1.
We have discovered 1,592 live websites that are affected by CVE-2026-24938.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 1,592 live websites (81% of Better Search install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 16 versions ( 94% of all versions) |
| 609 websites | |
| 223 websites | |
| 71 websites | |
| 69 websites | |
| 68 websites | |
| 60 websites | |
| 49 websites | |
| 42 websites | |
| 36 websites | |
| 28 websites |
| .com | 586 websites |
| .org | 167 websites |
| .de | 148 websites |
| .ru | 53 websites |
| .net | 52 websites |
| .fr | 47 websites |
| .co.uk | 38 websites |
| .nl | 38 websites |
| .it | 36 websites |
| .ca | 29 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***********.net | *,*** | ||
| *********.***.ua | **,*** | ||
| ******.*******.com | **,*** | ||
| ******.fr | **,*** | ||
| ****************.es | **,*** | ||
| *************.com | ***,*** | ||
| *************.com | ***,*** | ||
| ***********.com | ***,*** | ||
| ************.org | ***,*** | ||
| ******************.de | ***,*** |
FAQ