plugin

Relevanssi Premium Vulnerabilities

26 known security issues reported for the Relevanssi Premium WordPress plugin. Most recent disclosed Aug 4, 2026.

3 high 12 medium

Running Relevanssi Premium on your site? Check whether your installed version is affected.

Scan your site free

Relevanssi <= 4.27.1 and Relevanssi Premium <= 2.30.2 - Authenticated (Contributor+) SQL Injection

medium

The plugin provides an Admin Search page that allows users with the `edit_posts` capability to run Relevanssi searches from the WordPress dashboard. The AJAX handler accepts a URL-encoded `args` parameter, parses it into a `WP_Query`, and then passes user-controlled taxonomy query data into Relevanssi's taxonomy restri...

CVSS:
6.5
Affected:
up to 2.30.2
Fixed in:
2.30.3
Disclosed:
Aug 4, 2026

CVE-2026-15941 on NVD →

Relevanssi < 4.26.0 (Free) < 2.29.0 (Premium) - Authenticated (Contributor+) SQL Injection

medium

The Relevanssi Premium plugin for WordPress is vulnerable to SQL Injection in all versions up to 4.26.0 (Free) & 2.29.0 (Premium) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributo...

CVSS:
6.5
Affected:
up to 2.29.0
Fixed in:
2.29.0
Disclosed:
Dec 17, 2025

CVE-2025-14719 on NVD →

Relevanssi <= 4.24.5 (Free) and <= 2.27.6 (Premium) - Unauthenticated Stored Cross-Site Scripting via Excerpt Highlights

medium

The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Excerpt Highlights in all versions up to, and including, 4.24.5 (Free) and 2.27.6 (Premium) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to injec...

CVSS:
4.7
Affected:
up to 2.27.6
Fixed in:
2.27.7
Disclosed:
May 30, 2025

CVE-2025-5016 on NVD →

Relevanssi <= 4.24.4 (Free) and <= 2.27.5 (Premium) - Unauthenticated SQL Injection

high

The Relevanssi – A Better Search plugin for WordPress is vulnerable to time-based SQL Injection via the cats and tags query parameters in all versions up to, and including, 4.24.4 (Free) and <= 2.27.5 (Premium) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existin...

CVSS:
7.5
Affected:
up to 2.27.5
Fixed in:
2.27.6
Disclosed:
May 12, 2025

CVE-2025-4396 on NVD →

Relevanssi <= 4.24.3 (Free) and <= 2.27.4 (Premium) - Unauthenticated Stored Cross-Site Scripting via Search Highlights

medium

The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the highlights functionality in all versions up to, and including, 4.24.3 (Free) and <= 2.27.4 (Premium), due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attacker...

CVSS:
6.1
Affected:
up to 2.27.4
Fixed in:
2.27.5
Disclosed:
May 6, 2025

CVE-2025-4054 on NVD →

Relevanssi – A Better Search <= 4.23.0 (Free) and <= 2.26.0 (Premium) - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom name field in all versions up to, and including, 4.23.0 (Free) and 2.26.0 (Premium), due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject ar...

CVSS:
6.4
Affected:
up to 2.26.0
Fixed in:
2.26.1
Disclosed:
Sep 17, 2024

CVE-2024-9021 on NVD →

Relevanssi <= 4.22.2 (Free) and <= 2.25.1 (Premium) - Unauthenticated Information Exposure

medium

The Relevanssi – A Better Search plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.22.2 (Free) and 2.25.1 (Premium) via the relevanssi_do_query() due to insufficient limitations on the posts that are returned when searching. This makes it possible for unauthenticated att...

CVSS:
5.3
Affected:
up to 2.25.1
Fixed in:
2.25.2
Disclosed:
Aug 15, 2024

CVE-2024-7630 on NVD →

Relevanssi Premium [relevanssi-premium] < 2.25.2

unknown

[en] The Relevanssi – A Better Search plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 4.22.1. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on...

Affected:
up to 2.25.2
Fixed in:
2.25.2
Disclosed:
Apr 9, 2024

CVE-2024-3214 on NVD →

Relevanssi – A Better Search <= 4.22.1 - Unauthenticated Second Order CSV Injection

medium

The Relevanssi – A Better Search plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 4.22.1. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a loc...

CVSS:
5.8
Affected:
up to 2.25.1
Fixed in:
2.25.2
Disclosed:
Apr 4, 2024

CVE-2024-3214 on NVD →

Relevanssi – A Better Search <= 4.22.1 - Missing Authorization to Unauthenticated Count Option Update

medium

The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the relevanssi_update_counts() function in all versions up to, and including, 4.22.1. This makes it possible for unauthenticated attackers to execute expensive queries on the app...

CVSS:
5.3
Affected:
up to 2.25.1
Fixed in:
2.25.2
Disclosed:
Apr 4, 2024

CVE-2024-3213 on NVD →

Relevanssi – A Better Search <= 4.22.0 (Free) and <= 2.25.0 (Premium) - Missing Authorization to Unauthenticated Query Log Export

medium

The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relevanssi_export_log_check() function in all versions up to, and including, 4.22.0 (Free) and 2.25.0 (Premium). This makes it possible for unauthenticated attackers to export the...

CVSS:
5.3
Affected:
up to 2.25.0
Fixed in:
2.25.1
Disclosed:
Feb 22, 2024

CVE-2024-1380 on NVD →

Relevanssi Pro < 2.25 - Unauthenticated Sensitive Information Exposure

medium

The Relevanssi – A Better Search (Pro) plugin for WordPress is vulnerable to Sensitive Information Exposure in versions before 2.25. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 2.25
Fixed in:
2.25
Disclosed:
Jan 31, 2024

Relevanssi Premium [relevanssi-premium] < 2.25

unknown

The Relevanssi – A Better Search (Pro) plugin for WordPress is vulnerable to Sensitive Information Exposure in versions before 2.25. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

Affected:
up to 2.25
Fixed in:
2.25
Disclosed:
Jan 31, 2024

Relevanssi <= 4.21.2 (Free) and < 2.25.0 (Premium) - Missing Authorization to Unauthorized Post Access

medium

The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized access of data due to insufficient limitation of a user controlled key in all versions up to, and including, 4.21.2 (Free) and < 2.25.0 (Premium). This makes it possible for unauthenticated attackers to view private and draft posts that...

CVSS:
5.3
Affected:
up to 2.25.0
Fixed in:
2.25.0
Disclosed:
Jan 4, 2024

CVE-2023-7199 on NVD →

Relevanssi Premium [relevanssi-premium] < 2.25.0

unknown

The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized access of data due to insufficient limitation of a user controlled key in all versions up to, and including, 4.21.2 (Free) and < 2.25.0 (Premium). This makes it possible for unauthenticated attackers to view private and draft posts that...

Affected:
up to 2.25.0
Fixed in:
2.25.0
Disclosed:
Jan 4, 2024

Relevanssi – A Better Search < 4.14.6 & Relevanssi – A Better Search Pro < 2.16.5 - Missing Authorization

medium

The Relevanssi – A Better Search plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on several functions in versions before 4.14.6 in the free version and 2.16.5 in the PRO version. This makes it possible for authenticated attackers with Subscriber-level roles and above to perfo...

CVSS:
6.3
Affected:
up to 2.16.5
Fixed in:
2.16.5
Disclosed:
Feb 15, 2022

Relevanssi Premium [relevanssi-premium] < 2.16.5

unknown

Unauthorized AJAX Calls vulnerability discovered by Jan w Oleju in WordPress Relevanssi Premium plugin (versions <= 2.16.4).

Affected:
up to 2.16.5
Fixed in:
2.16.5
Disclosed:
Feb 15, 2022

Relevanssi - A Better Search Free & Premium <= 2.16.3 & 4.14.3 - Stored Cross-Site Scripting

high

The Relevanssi - A Better Search Free & Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘$query_link ’ parameter in versions up to, and including, 2.16.3 & 4.14.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject...

CVSS:
7.2
Affected:
up to 2.16.3
Fixed in:
2.16.4
Disclosed:
Oct 19, 2021

Relevanssi Premium [relevanssi-premium] < 1.14.6.1

unknown

[en] The Relevanssi Premium plugin before 1.14.6.1 for WordPress has SQL injection with resultant unsafe unserialization.

Affected:
up to 1.14.6.1
Fixed in:
1.14.6.1
Disclosed:
Sep 13, 2019

CVE-2016-10949 on NVD →

Relevanssi Premium < 1.14.6.1 - SQL Injection

high

The Relevanssi Premium plugin before 1.14.6.1 for WordPress has SQL injection with resultant unsafe unserialization.

CVSS:
8.8
Affected:
up to 1.14.6.1
Fixed in:
1.14.6.1
Disclosed:
Nov 17, 2016

CVE-2016-10949 on NVD →

Relevanssi Premium [relevanssi-premium] < 1.14.5

unknown

This plugin is prone to a SQL injection and PHP object injection vulnerabilities. Update the plugin.

Affected:
up to 1.14.5
Fixed in:
1.14.5
Disclosed:
Nov 17, 2016

Relevanssi Premium [relevanssi-premium] < 2.16.5

unknown

The plugins do not have authorisation and CSRF checks in some of their AJAX actions, allowing any authenticated users, such as subscriber, to call them. This could disclose information to subscribers, as well as allow them to truncate the index, which will disable the search

Affected:
up to 2.16.5
Fixed in:
2.16.5

Relevanssi Premium [relevanssi-premium] < 2.25

unknown

Update the WordPress Relevanssi Premium plugin to the latest available version (at least 2.25). An unknown person discovered and reported this Sensitive Data Exposure vulnerability in WordPress Relevanssi Premium Plugin. This vulnerability has been fixed in version 2.25. Have additional information or questions about...

Affected:
up to 2.25
Fixed in:
2.25

Relevanssi Premium [relevanssi-premium] < 2.25

unknown

The plugin is vulnerable to Sensitive Information Exposure, allowing unauthenticated attackers to extract sensitive user or configuration data.

Affected:
up to 2.25
Fixed in:
2.25

Relevanssi Premium [relevanssi-premium] < 2.27.5

unknown
Affected:
up to 2.27.5
Fixed in:
2.27.5

CVE-2025-4396 on NVD →

Relevanssi Premium [relevanssi-premium] < 2.27.7

unknown
Affected:
up to 2.27.7
Fixed in:
2.27.7

CVE-2025-5016 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database