WordPress WP Search Analytics Plugin <= 1.4.7 is vulnerable to Cross Site Scripting (XSS)
Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Cornel Raiu WP Search Analytics plugin <= 1.4.7 versions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Unauthenticated reflected XSS in WP Search Analytics plugin <=1.4.7 allows attackers to inject arbitrary web scripts via crafted requests.
Vulnerability
The WP Search Analytics plugin by Cornel Raiu, versions 1.4.7 and earlier, contains a reflected Cross-Site Scripting (XSS) vulnerability. The plugin fails to properly sanitize user input before reflecting it back in the response, allowing an unauthenticated attacker to inject arbitrary JavaScript. The vulnerability is present in the plugin's admin pages or search analytics functionality. [1]
Exploitation
An attacker can exploit this vulnerability by crafting a malicious URL containing a payload in a parameter that is reflected without sanitization. The victim must be logged into WordPress and click the link. No authentication is required to trigger the reflection, but the victim must have access to the affected admin page. The attacker does not need any special privileges.
Impact
Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser. This can lead to session hijacking, defacement, or theft of sensitive information such as cookies or login credentials. The impact is limited to the victim's session and browser.
Mitigation
The vulnerability is fixed in version 1.5.0 of the plugin, released on 2026-05-07 (according to the plugin page). Users should update to version 1.5.0 or later. No workarounds are provided. The plugin is not listed on CISA's KEV as of this writing. [1]
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=1.4.7
- Cornel Raiu/WP Search Analyticsv5Range: n/a
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.