
CVE-2026-2837 The Ricerca – advanced search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin's settings in all versions up to, and including, 1.1.12 due t… https://www.cve.org/CVERecord?id=CVE-2026-2837
Post summary
Ricerca advanced search WordPress plugin versions up to 1.1.12 are vulnerable to stored XSS through plugin settings, as documented by CVE-2026-2837.
