CVE-2026-24938

WordPress Better Search plugin <= 4.2.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Better Search better-search allows Stored XSS.This issue affects Better Search: from n/a through <= 4.2.1.


We have discovered 1,592 live websites that are affected by CVE-2026-24938.

Run a Free Instant Scan




Affected Software

Product  Better Search
Category Wordpress Plugins
Vulnerable Domains1,592 live websites (81% of Better Search install base)
Vulnerable Versions
  • from 0 through 4.2.1
Vulnerable Versions Count16 versions ( 94% of all versions)



Details

  • Published - Feb 3, 2026
  • Updated - Feb 3, 2026

Credits

  • Peter Thaleikis | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-24938
United States609 websites



Germany223 websites
Russia71 websites
France69 websites
GB68 websites
Netherlands60 websites
Italy49 websites
Canada42 websites
Switzerland36 websites
Spain28 websites

Website Distribution by TLD

Number of websites using CVE-2026-24938
.com586 websites
.org167 websites
.de148 websites
.ru53 websites
.net52 websites
.fr47 websites
.co.uk38 websites
.nl38 websites
.it36 websites
.ca29 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-24938

Top websites that are affected by CVE-2026-24938. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.net United States*,***
*********.***.ua Ukraine**,***
******.*******.com United States**,***
******.fr Switzerland**,***
****************.es United States**,***
*************.com United States***,***
*************.com Spain***,***
***********.com United States***,***
************.org United States***,***
******************.de Germany***,***
See full domain list

FAQ

A total of 1,592 websites have been identified as vulnerable to CVE-2026-24938, based on global website indexing conducted by WebTechSurvey.
The Better Search is affected by the CVE-2026-24938 vulnerability.
Better Search versions up to and including 4.2.1 are vulnerable to CVE-2026-24938.