Relevanssi <= 4.27.1 and Relevanssi Premium <= 2.30.2 - Authenticated (Contributor+) SQL Injection
medium
The plugin provides an Admin Search page that allows users with the `edit_posts` capability to run Relevanssi searches from the WordPress dashboard. The AJAX handler accepts a URL-encoded `args` parameter, parses it into a `WP_Query`, and then passes user-controlled taxonomy query data into Relevanssi's taxonomy restri...
- CVSS:
- 6.5
- Affected:
- up to 4.27.1
- Fixed in:
- 4.27.2
- Disclosed:
- Aug 4, 2026
CVE-2026-15941 on NVD →
Relevanssi – A Better Search [relevanssi] < 4.26.0
unknown
[en] The Relevanssi WordPress plugin before 4.26.0, Relevanssi Premium WordPress plugin before 2.29.0 do not sanitize and escape a parameter before using it in a SQL statement, allowing contributor and above roles to perform SQL injection attacks
- Affected:
- up to 4.26.0
- Fixed in:
- 4.26.0
- Disclosed:
- Jan 7, 2026
CVE-2025-14719 on NVD →
Relevanssi < 4.26.0 (Free) < 2.29.0 (Premium) - Authenticated (Contributor+) SQL Injection
medium
The Relevanssi Premium plugin for WordPress is vulnerable to SQL Injection in all versions up to 4.26.0 (Free) & 2.29.0 (Premium) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributo...
- CVSS:
- 6.5
- Affected:
- up to 4.26.0
- Fixed in:
- 4.26.0
- Disclosed:
- Dec 17, 2025
CVE-2025-14719 on NVD →
Relevanssi <= 4.24.5 (Free) and <= 2.27.6 (Premium) - Unauthenticated Stored Cross-Site Scripting via Excerpt Highlights
medium
The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Excerpt Highlights in all versions up to, and including, 4.24.5 (Free) and 2.27.6 (Premium) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to injec...
- CVSS:
- 4.7
- Affected:
- up to 4.24.5
- Fixed in:
- 4.24.6
- Disclosed:
- May 30, 2025
CVE-2025-5016 on NVD →
Relevanssi <= 4.24.4 (Free) and <= 2.27.5 (Premium) - Unauthenticated SQL Injection
high
The Relevanssi – A Better Search plugin for WordPress is vulnerable to time-based SQL Injection via the cats and tags query parameters in all versions up to, and including, 4.24.4 (Free) and <= 2.27.5 (Premium) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existin...
- CVSS:
- 7.5
- Affected:
- up to 4.24.4
- Fixed in:
- 4.24.5
- Disclosed:
- May 12, 2025
CVE-2025-4396 on NVD →
Relevanssi <= 4.24.3 (Free) and <= 2.27.4 (Premium) - Unauthenticated Stored Cross-Site Scripting via Search Highlights
medium
The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the highlights functionality in all versions up to, and including, 4.24.3 (Free) and <= 2.27.4 (Premium), due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attacker...
- CVSS:
- 6.1
- Affected:
- up to 4.24.3
- Fixed in:
- 4.24.4
- Disclosed:
- May 6, 2025
CVE-2025-4054 on NVD →
Relevanssi – A Better Search [relevanssi] < 4.23.1
unknown
[en] In the process of testing the Relevanssi WordPress plugin before 4.23.1, a vulnerability was found that allows you to implement Stored XSS on behalf of the Contributor+ by embedding malicious script, which entails account takeover backdoor
- Affected:
- up to 4.23.1
- Fixed in:
- 4.23.1
- Disclosed:
- Oct 8, 2024
CVE-2024-9021 on NVD →
Relevanssi – A Better Search <= 4.23.0 (Free) and <= 2.26.0 (Premium) - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom name field in all versions up to, and including, 4.23.0 (Free) and 2.26.0 (Premium), due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject ar...
- CVSS:
- 6.4
- Affected:
- up to 4.23.0
- Fixed in:
- 4.23.1
- Disclosed:
- Sep 17, 2024
CVE-2024-9021 on NVD →
Relevanssi – A Better Search [relevanssi] < 4.23.0
unknown
[en] The Relevanssi – A Better Search plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.22.2 via the relevanssi_do_query() due to insufficient limitations on the posts that are returned when searching. This makes it possible for unauthenticated attackers to extract poten...
- Affected:
- up to 4.23.0
- Fixed in:
- 4.23.0
- Disclosed:
- Aug 16, 2024
CVE-2024-7630 on NVD →
Relevanssi <= 4.22.2 (Free) and <= 2.25.1 (Premium) - Unauthenticated Information Exposure
medium
The Relevanssi – A Better Search plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.22.2 (Free) and 2.25.1 (Premium) via the relevanssi_do_query() due to insufficient limitations on the posts that are returned when searching. This makes it possible for unauthenticated att...
- CVSS:
- 5.3
- Affected:
- up to 4.22.2
- Fixed in:
- 4.23.0
- Disclosed:
- Aug 15, 2024
CVE-2024-7630 on NVD →
Relevanssi – A Better Search [relevanssi] < 4.22.2
unknown
[en] The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the relevanssi_update_counts() function in all versions up to, and including, 4.22.1. This makes it possible for unauthenticated attackers to execute expensive queries on th...
- Affected:
- up to 4.22.2
- Fixed in:
- 4.22.2
- Disclosed:
- Apr 9, 2024
CVE-2024-3213 on NVD →
Relevanssi – A Better Search [relevanssi] < 4.22.2
unknown
[en] The Relevanssi – A Better Search plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 4.22.1. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on...
- Affected:
- up to 4.22.2
- Fixed in:
- 4.22.2
- Disclosed:
- Apr 9, 2024
CVE-2024-3214 on NVD →
Relevanssi – A Better Search <= 4.22.1 - Unauthenticated Second Order CSV Injection
medium
The Relevanssi – A Better Search plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 4.22.1. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a loc...
- CVSS:
- 5.8
- Affected:
- up to 4.22.1
- Fixed in:
- 4.22.2
- Disclosed:
- Apr 4, 2024
CVE-2024-3214 on NVD →
Relevanssi – A Better Search <= 4.22.1 - Missing Authorization to Unauthenticated Count Option Update
medium
The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the relevanssi_update_counts() function in all versions up to, and including, 4.22.1. This makes it possible for unauthenticated attackers to execute expensive queries on the app...
- CVSS:
- 5.3
- Affected:
- up to 4.22.1
- Fixed in:
- 4.22.2
- Disclosed:
- Apr 4, 2024
CVE-2024-3213 on NVD →
Relevanssi – A Better Search [relevanssi] < 4.22.1
unknown
[en] The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relevanssi_export_log_check() function in all versions up to, and including, 4.22.0. This makes it possible for unauthenticated attackers to export the query log data. The ven...
- Affected:
- up to 4.22.1
- Fixed in:
- 4.22.1
- Disclosed:
- Mar 13, 2024
CVE-2024-1380 on NVD →
Relevanssi – A Better Search <= 4.22.0 (Free) and <= 2.25.0 (Premium) - Missing Authorization to Unauthenticated Query Log Export
medium
The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relevanssi_export_log_check() function in all versions up to, and including, 4.22.0 (Free) and 2.25.0 (Premium). This makes it possible for unauthenticated attackers to export the...
- CVSS:
- 5.3
- Affected:
- up to 4.22.0
- Fixed in:
- 4.22.1
- Disclosed:
- Feb 22, 2024
CVE-2024-1380 on NVD →
Relevanssi – A Better Search [relevanssi] < 4.22.0
unknown
[en] The Relevanssi WordPress plugin before 4.22.0, Relevanssi Premium WordPress plugin before 2.25.0 allows any unauthenticated user to read draft and private posts via a crafted request
- Affected:
- up to 4.22.0
- Fixed in:
- 4.22.0
- Disclosed:
- Jan 29, 2024
CVE-2023-7199 on NVD →
Relevanssi <= 4.21.2 (Free) and < 2.25.0 (Premium) - Missing Authorization to Unauthorized Post Access
medium
The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized access of data due to insufficient limitation of a user controlled key in all versions up to, and including, 4.21.2 (Free) and < 2.25.0 (Premium). This makes it possible for unauthenticated attackers to view private and draft posts that...
- CVSS:
- 5.3
- Affected:
- up to 4.21.2
- Fixed in:
- 4.22.0
- Disclosed:
- Jan 4, 2024
CVE-2023-7199 on NVD →
Relevanssi – A Better Search < 4.14.6 & Relevanssi – A Better Search Pro < 2.16.5 - Missing Authorization
medium
The Relevanssi – A Better Search plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on several functions in versions before 4.14.6 in the free version and 2.16.5 in the PRO version. This makes it possible for authenticated attackers with Subscriber-level roles and above to perfo...
- CVSS:
- 6.3
- Affected:
- up to 4.14.6
- Fixed in:
- 4.14.6
- Disclosed:
- Feb 15, 2022
Relevanssi – A Better Search [relevanssi] < 4.14.6
unknown
The Relevanssi – A Better Search plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on several functions in versions before 4.14.6 in the free version and 2.16.5 in the PRO version. This makes it possible for authenticated attackers with Subscriber-level roles and above to perfo...
- Affected:
- up to 4.14.6
- Fixed in:
- 4.14.6
- Disclosed:
- Feb 15, 2022
Relevanssi – A Better Search [relevanssi] < 4.14.6
unknown
Unauthorized AJAX Calls vulnerability discovered by Jan w Oleju in WordPress Relevanssi – A Better Search plugin (versions <= 4.14.5).
- Affected:
- up to 4.14.6
- Fixed in:
- 4.14.6
- Disclosed:
- Feb 15, 2022
Relevanssi - A Better Search Free & Premium <= 2.16.3 & 4.14.3 - Stored Cross-Site Scripting
high
The Relevanssi - A Better Search Free & Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘$query_link ’ parameter in versions up to, and including, 2.16.3 & 4.14.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject...
- CVSS:
- 7.2
- Affected:
- up to 4.14.3
- Fixed in:
- 4.14.4
- Disclosed:
- Oct 19, 2021
Relevanssi – A Better Search [relevanssi] < 4.14.3
unknown
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress Relevanssi plugin (versions <= 4.14.2).
- Affected:
- up to 4.14.3
- Fixed in:
- 4.14.3
- Disclosed:
- Oct 19, 2021
Relevanssi – A Better Search [relevanssi] < 4.14.4
unknown
The Relevanssi - A Better Search Free & Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘$query_link ’ parameter in versions up to, and including, 2.16.3 & 4.14.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject...
- Affected:
- up to 4.14.4
- Fixed in:
- 4.14.4
- Disclosed:
- Oct 19, 2021
Relevanssi <= 3.6.0 - Authenticated (Admin+) SQL Injection
high
The Relevanssi plugin for WordPress is vulnerable to generic SQL Injection via the ‘relevanssi_weight_’ parameter in versions up to, and including, 3.6.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated at...
- CVSS:
- 8.7
- Affected:
- up to 3.6.1
- Fixed in:
- 3.6.1
- Disclosed:
- Apr 10, 2018
Relevanssi – A Better Search [relevanssi] < 3.6.1
unknown
The Relevanssi plugin for WordPress is vulnerable to generic SQL Injection via the ‘relevanssi_weight_’ parameter in versions up to, and including, 3.6.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated at...
- Affected:
- up to 3.6.1
- Fixed in:
- 3.6.1
- Disclosed:
- Apr 10, 2018
Relevanssi – A Better Search [relevanssi] < 4.0.5
unknown
[en] Cross-site scripting (XSS) vulnerability in lib/interface.php of the Relevanssi plugin 4.0.4 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the tab GET parameter.
- Affected:
- up to 4.0.5
- Fixed in:
- 4.0.5
- Disclosed:
- Apr 4, 2018
CVE-2018-9034 on NVD →
Relevanssi <= 4.0.4 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in lib/interface.php of the Relevanssi plugin 4.0.4 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the tab GET parameter.
- CVSS:
- 5.4
- Affected:
- up to 4.0.4
- Fixed in:
- 4.0.5
- Disclosed:
- Mar 30, 2018
CVE-2018-9034 on NVD →
Relevanssi – A Better Search [relevanssi] < 3.5.8
unknown
[en] WordPress plugin Relevanssi version 3.5.7.1 is vulnerable to stored XSS resulting in attacker being able to execute JavaScript on the affected site
- Affected:
- up to 3.5.8
- Fixed in:
- 3.5.8
- Disclosed:
- Jul 13, 2017
CVE-2017-1000038 on NVD →
Relevanssi – A Better Search <= 3.5.7.1 - Stored Cross-Site Scripting
medium
WordPress plugin Relevanssi version 3.5.7.1 is vulnerable to stored XSS resulting in attacker being able to execute JavaScript on the affected site
- CVSS:
- 6.1
- Affected:
- up to 3.5.8
- Fixed in:
- 3.5.8
- Disclosed:
- Feb 28, 2017
CVE-2017-1000038 on NVD →
Relevanssi – A Better Search [relevanssi] < 3.3
unknown
Because of this vulnerability, remote authenticated users can execute arbitrary SQL commands.
Update the plugin.
- Affected:
- up to 3.3
- Fixed in:
- 3.3
- Disclosed:
- May 15, 2015
Relevanssi – A Better Search < 3.3.8 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in the Relevanssi plugin before 3.3.8 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVSS:
- 6.1
- Affected:
- up to 3.3.8
- Fixed in:
- 3.3.8
- Disclosed:
- Jan 3, 2015
CVE-2014-9443 on NVD →
Relevanssi – A Better Search [relevanssi] < 3.3.8
unknown
[en] Cross-site scripting (XSS) vulnerability in the Relevanssi plugin before 3.3.8 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- Affected:
- up to 3.3.8
- Fixed in:
- 3.3.8
- Disclosed:
- Jan 2, 2015
CVE-2014-9443 on NVD →
Relevanssi – A Better Search [relevanssi] < 3.4
unknown
Relevanssi plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, compromise the access and application or exploit hidden vulnerabilities in the underlying database.
Update the plugin.
- Affected:
- up to 3.4
- Fixed in:
- 3.4
- Disclosed:
- Mar 4, 2014
Relevanssi <= 3.3 - SQL Injection
critical
The Relevanssi plugin for WordPress is vulnerable to SQL Injection via the ‘category_name’ parameter in versions up to, and including, 3.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attackers to append additional S...
- CVSS:
- 9.8
- Affected:
- up to 3.3
- Fixed in:
- 3.3.1
- Disclosed:
- Feb 25, 2014
Relevanssi – A Better Search [relevanssi] < 3.3.1
unknown
The Relevanssi plugin for WordPress is vulnerable to SQL Injection via the ‘category_name’ parameter in versions up to, and including, 3.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attackers to append additional S...
- Affected:
- up to 3.3.1
- Fixed in:
- 3.3.1
- Disclosed:
- Feb 25, 2014
Relevanssi – A Better Search [relevanssi] < 2.7.3
unknown
Relevanssi plugin is prone to a stored cross-site scripting vulnerability that exists because of "search Query" variable is displayed and logged unsanitized in the "User Searches" section in the admin Dashboard. This vulnerability allows an attacker to inject malicious HTML code.
- Affected:
- up to 2.7.3
- Fixed in:
- 2.7.3
- Disclosed:
- Feb 24, 2011
Relevanssi – A Better Search [relevanssi] < 4.22
unknown
Update the WordPress Relevanssi plugin to the latest available version (at least 4.22).
An unknown person discovered and reported this Sensitive Data Exposure vulnerability in WordPress Relevanssi Plugin. This vulnerability has been fixed in version 4.22.
Have additional information or questions about this entry? Get...
- Affected:
- up to 4.22
- Fixed in:
- 4.22
Relevanssi – A Better Search [relevanssi] < 3.3
unknown
The Relevanssi – A Better Search WordPress plugin was affected by an Unspecified SQL Injection security vulnerability.
- Affected:
- up to 3.3
- Fixed in:
- 3.3
Relevanssi – A Better Search [relevanssi] < 2.7.3
unknown
The Relevanssi – A Better Search WordPress plugin was affected by a Stored XSS security vulnerability.
- Affected:
- up to 2.7.3
- Fixed in:
- 2.7.3
Relevanssi – A Better Search [relevanssi] < 3.6.1
unknown
The Relevanssi – A Better Search WordPress plugin was affected by an Authenticated Admin SQL Injection security vulnerability.
- Affected:
- up to 3.6.1
- Fixed in:
- 3.6.1
Relevanssi – A Better Search [relevanssi] < 4.24.4
unknown
- Affected:
- up to 4.24.4
- Fixed in:
- 4.24.4
CVE-2025-4054 on NVD →
Relevanssi – A Better Search [relevanssi] < 4.24.5
unknown
- Affected:
- up to 4.24.5
- Fixed in:
- 4.24.5
CVE-2025-4396 on NVD →
Relevanssi – A Better Search [relevanssi] < 4.24.6
unknown
- Affected:
- up to 4.24.6
- Fixed in:
- 4.24.6
CVE-2025-5016 on NVD →
Relevanssi – A Better Search [relevanssi] < 4.14.3
unknown
The plugin does not sanitise and escape user searches before outputting them in the related admin dashboard when the feature is enabled
- Affected:
- up to 4.14.3
- Fixed in:
- 4.14.3
Relevanssi – A Better Search [relevanssi] < 4.14.6
unknown
The plugins do not have authorisation and CSRF checks in some of their AJAX actions, allowing any authenticated users, such as subscriber, to call them. This could disclose information to subscribers, as well as allow them to truncate the index, which will disable the search
- Affected:
- up to 4.14.6
- Fixed in:
- 4.14.6