Medium severity5.3NVD Advisory· Published Sep 5, 2024· Updated Jun 17, 2026
CVE-2024-6835
CVE-2024-6835
Description
The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 5.5.6 via the ajax_load_posts function. This makes it possible for unauthenticated attackers to extract text data from password-protected posts using the boolean-based attack on the AJAX search form
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- vinod-dalvi/Ivory Search – WordPress Search Pluginv5Range: 0
- Range: <=5.5.6
Patches
Vulnerability mechanics
References
4- plugins.trac.wordpress.org/changeset/3145289/nvdPatch
- www.wordfence.com/threat-intel/vulnerabilities/id/013f7c26-8348-4c54-af61-473a720a5095nvdThird Party Advisory
- plugins.trac.wordpress.org/browser/add-search-to-menu/tags/5.5.6/public/class-is-ajax.phpnvdProduct
- plugins.trac.wordpress.org/browser/add-search-to-menu/tags/5.5.6/public/partials/is-ajax-results.phpnvdProduct
News mentions
0No linked articles in our index yet.