11.22
- Security: fixed a stored XSS vulnerability in the search-keywords path of the visitor-tracking endpoint. An unauthenticated visitor could submit a crafted "referer" (e.g. a search-engine URL whose query string contained a percent-encoded HTML payload) that survived URL sanitization, was decoded back to markup, stored in the keywords table, and executed in the admin dashboard when viewing the Latest Search Words / keywords report. Extracted keywords are now stripped of any HTML on storage and escaped on output (URL via esc_url, text via esc_html), in both the table view and the Excel export. This completes the 11.19 tracking-endpoint hardening by closing the sibling "referer" parameter.