Wordpress Alert: Reflected cross-site scripting in search

A crafted search URL echoes unsafe text into the page. A visitor following the link may execute attacker-controlled script.

What it looks like

A crafted search URL echoes unsafe text into the page.

Why it matters

A visitor following the link may execute attacker-controlled script.

What to check

Test search templates and escape the displayed query.

Documentation

This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WordPress output escaping.