Medium severity4.8NVD Advisory· Published Feb 7, 2022· Updated Jun 17, 2026
CVE-2021-25105
CVE-2021-25105
Description
The Ivory Search WordPress plugin before 5.4.1 does not escape some of the Form settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- WordPress/Ivory Searchdescription
- Range: <5.4.1
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/a9ab9e84-7f5e-4e7c-8647-114d9e02e59fnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.