Sceawere

Vulnerability Detail

CVE-2026-95598UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Reflected XSS in Search in Place

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
codepeople
Product
Search in Place
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople Search in Place search-in-place allows Reflected XSS.This issue affects Search in Place: from n/a through 1.5.5.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-09T10:16:42.643Z",
  "pubdate": "2026-10-09T10:16:42.643Z",
  "executiveSummary": "The Search in Place plugin for WordPress is susceptible to a Reflected Cross-Site Scripting (XSS) vulnerability due to improper neutralization of user-supplied input during web page generation.\nThis vulnerability is classified under CWE-79, Improper Neutralization of Input During Web Page Generation.\nThe flaw allows an unauthenticated attacker to inject malicious client-side scripts into the search results page, which are subsequently executed within the context of the victim's browser session.\nThe risk implication is significant, as successful exploitation can lead to unauthorized access to sensitive user data, session hijacking, cookie theft, or the execution of unauthorized administrative actions on behalf of the victim.\nAffected systems include all versions of the Search in Place plugin from n/a through 1.5.5.\nExploitation requires the attacker to trick a legitimate user into clicking a crafted URL containing malicious script payloads, typically delivered via phishing campaigns or malicious link injections.",
  "technicalDetails": "The vulnerability originates from the application's failure to adequately sanitize or encode search parameters provided by the user before reflecting them back into the HTML response document.\nIn the affected versions of Search in Place (up to 1.5.5), the plugin processes search queries directly from the URL query parameters without applying context-aware output encoding. This creates a classic Reflected XSS condition where the server-side logic echoes the malicious payload directly into the document object model (DOM) of the generated page.\nThe attack flow begins when an attacker crafts a malicious URL containing a JavaScript payload within the search parameter. For example, by navigating to a site utilizing the plugin with a query string modified to include <script>alert(document.domain)</script>, the browser interprets the injected tags as executable code rather than plain text.\nBecause the input is processed without strict validation or proper escaping of special characters such as <, >, \", and ', the browser's script engine executes the payload in the context of the vulnerable origin. This bypasses same-origin policy protections intended to isolate scripts from unauthorized domains.\nThe vulnerability does not require authentication or elevated administrative privileges, making it accessible to any remote, unauthenticated attacker capable of inducing a user to navigate to the crafted URL.\nPost-exploitation impact is severe. Since the script executes within the victim's session, the attacker can access sensitive information available to the authenticated user, including session tokens, CSRF tokens, or personal account details. Furthermore, the attacker can manipulate the DOM to present fraudulent content to the user, conduct unauthorized actions such as creating new administrative accounts, or perform silent exfiltration of data captured during the victim's session.\nGiven that the search functionality is typically publicly exposed and processed server-side, the attack surface encompasses all installations of the plugin where the search results are rendered using the vulnerable, unencoded output mechanism."
}
CVE-2026-95598: Reflected XSS in Search in Place (HIGH Severity, CVSS: 7.1) | Sceawere