Sceawere
Vulnerability Detail
CVE-2026-96352UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated XSS in YITH WooCommerce Ajax Search
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 3h ago
- Vendor
- YITHEMES
- Product
- YITH WooCommerce Ajax Search
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Cross Site Scripting (XSS) in YITH WooCommerce Ajax Search <= 2.28.0 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-09-30T13:17:30.350Z",
"pubdate": "2026-09-30T13:17:30.350Z",
"executiveSummary": "The YITH WooCommerce Ajax Search plugin, in versions 2.28.0 and below, contains an unauthenticated Stored/Reflected Cross-Site Scripting (XSS) vulnerability. This security flaw allows remote, unauthenticated attackers to inject malicious JavaScript into the search functionality of the affected WordPress site.\nThe vulnerability stems from improper sanitization and validation of user-supplied input provided to the search parameters. An attacker can leverage this weakness to execute arbitrary scripts in the context of a victim's browser session, leading to potential session hijacking, unauthorized actions on behalf of the user, or the redirection of visitors to malicious external domains.\nThe impact is significant, as it does not require administrative privileges or complex authentication to exploit. All installations of YITH WooCommerce Ajax Search using the affected version range are susceptible. Successful exploitation may compromise user data, steal authentication cookies, or deface the website interface. Security administrators are urged to restrict access or update the plugin to a secure version to mitigate the risk of unauthorized client-side code execution.",
"technicalDetails": "The vulnerability resides within the search request handling logic of the YITH WooCommerce Ajax Search plugin. Specifically, the plugin fails to sufficiently sanitize user-controllable input passed via search parameters before echoing the content back into the HTML response generated for the browser. This lack of output encoding transforms the search field into a vector for injecting malicious JavaScript payloads.\nExploitation is achieved through a crafted HTTP GET or POST request targeting the search function. An attacker can append a malicious script payload (e.g., <script>alert('XSS')</script>) to the search query parameter. Because the application processes this input and renders it within the DOM without proper sanitization, the browser interprets the injected content as executable code rather than plain text.\nThe attack flow begins when an attacker sends a specially crafted URL or form submission containing a payload to the vulnerable endpoint. When a victim clicks the link or performs a search, the payload is delivered to the browser. The vulnerable component reflects this input back into the page source of the search results page. Consequently, the browser executes the script in the security context of the origin site. This allows the attacker to perform actions such as stealing session tokens, performing unauthorized administrative operations via CSRF, or exfiltrating sensitive data visible on the page.\nThe scope of this vulnerability covers versions up to and including 2.28.0. As it is an unauthenticated vulnerability, no specific user roles, sessions, or prior knowledge of the target system are required. The attack is executable over the network via standard HTTP/HTTPS protocols, making it accessible to any remote actor capable of reaching the web server. The failure to implement context-aware output encoding (such as esc_html() or esc_js()) in the relevant PHP files responsible for search output generation is the root cause of the vulnerability. This behavior bypasses typical security controls, as the injected script runs with the same permissions as the legitimate site content, effectively breaking the Same-Origin Policy (SOP) regarding user data protection."
}