PT-2026-2831 · Searchwiz · Searchwiz

Athiwat Tiprasaharn

+6

·

Published

2026-01-14

·

Updated

2026-01-14

·

CVE-2026-0694

CVSS v3.1
6.4
VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
The SearchWiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in search results in all versions up to, and including, 1.0.0. This is due to the plugin using
esc attr()
instead of
esc html()
when outputting post titles in search results. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in post titles that will execute whenever a user performs a search and views the search results page.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-0694

Affected Products

Searchwiz