Site Search 360
Site Search 360 has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2025; 1 is fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 6.3, and the most serious one scores 6.4 out of 10. 2025 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Cross-Site Scripting.
1 of the records (50%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2025.
2 independent researchers contributed these findings, one record each. Site Search 360 is installed on roughly 400 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2025-39530Site Search 360 <= 2.1.7 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Site Search 360
Author
dsky
Site Search 360 replaces your standard WordPress search by a fast and precise on-site search on all your posts and pages. Site Search 360 is highly customizable and gives you detailed insights into search behavior. Site Search 360 is responsive and mobile ready so your search will work no matter what screen your visitors are on. Features Fast indexing and swift search and suggestions Result set clusters: Group search results of the same type together, e.g. all article matches and all matches on review pages. Drop-in replacement: in most cases you do not need to change a single configuration to enable the search instantly. Fast typeahead autocomplete search suggestions based on titles, tags, and author names. Custom taxonomy indexing: custom taxonomy terms can be indexed and even shown in the search results. Search results automatically update when you save, delete, or change search content. Easily customizable by CSS and the dashboard. Site Search 360 Search designer compatible. Getting started To get started, see the Installation instructions or check our full WordPress Integration Guide. Help Need help? Just post your question in the support forum.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C