Authenticated Persistent Cross-Site Scripting (XSS) Vulnerability in Ivory Search
Yesterday, the WordPress plugin Ivory Search was closed on WordPress Plugin Directory. Due to that being one of the 1,000 most popular plugins in that directory (it has 70,000+ installs), our systems warned us about the closure and we started checking over the plugin to see if there was a vulnerability we should be warning customers of our service about if they are using the plugin. We found the plugin contains code that looks to not be properly secured and confirmed that it contains at least a minor vulnerability. We would recommend not using the plugin unless it has received a thorough security review and all the issues are addressed.
We tested and confirmed that our new firewall plugin for WordPress protected against the proof of concept below, even before we discovered the vulnerability, as part of its protection against zero-day vulnerabilities. [Read more]