Search by Google
Search by Google has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Search by Google has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Que Thanh Tuan - Blue Rock. Search by Google is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 5.5.20.
CVE-2025-58832Search by Google <= 1.9 - Authenticated (Administrator+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Search by Google
Author
webvitalii
Search by Google Donate WordPress plugins “Search by Google” plugin adds Google search form widget. It helps user to search on site using Google. Widget options: “Title” (title of the widget); “Submit button text” (if left blank than “Google search” text will be used); “Search on site” (if left blank than Google will search on current site); Useful: “Page-list” – show list of pages with shortcodes “Iframe” – embed content WordPress Pro plugins
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C