{"error":0,"message":null,"data":{"name":"Relevanssi &#8211; A Better Search","plugin":"relevanssi","link":"https:\/\/wordpress.org\/plugins\/relevanssi\/","latest":"1789035000","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"e722f4bcf5a1b2a120e9b10ba12fd6d487957771e3030db0556377d3e93cd05f","name":"Relevanssi &#8211; A Better Search [relevanssi] < 4.0.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.0.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2018-9034","name":"CVE-2018-9034","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2018-9034","description":"[en] Cross-site scripting (XSS) vulnerability in lib\/interface.php of the Relevanssi plugin 4.0.4 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the tab GET parameter.","date":"2018-04-04"},{"id":"7d14ed96c295f082656769c8225510903dc42234","name":"WordPress Relevanssi plugin <=4.0.4 - Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/relevanssi\/vulnerability\/wordpress-relevanssi-plugin-4-0-4-cross-site-scripting-xss-vulnerability","description":"Cross-Site Scripting (XSS) vulnerability found in WordPress Relevanssi plugin (versions <=4.0.4). Attackers can inject arbitrary JavaScript or HTML via the GET parameter.","date":"2018-04-09"},{"id":"4423c8e26b179a016edf4d55de8c2adca859d717","name":"Relevanssi <= 4.0.4 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/relevanssi\/relevanssi-404-cross-site-scripting","description":"Cross-site scripting (XSS) vulnerability in lib\/interface.php of the Relevanssi plugin 4.0.4 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the tab GET parameter.","date":"2018-03-30"},{"id":"0cee5dac-1c27-4f81-becf-b54d2773c030","name":"Relevanssi &lt;= 4.0.4 - Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/0cee5dac-1c27-4f81-becf-b54d2773c030","description":"The Relevanssi &ndash; A Better Search WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"99b65ffb3aa5d47e61426df164cf116a15e0c667c49fa2a4295047c8a2edb547","name":"Relevanssi &#8211; A Better Search [relevanssi] < 3.5.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.5.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2017-1000038","name":"CVE-2017-1000038","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2017-1000038","description":"[en] WordPress plugin Relevanssi version 3.5.7.1 is vulnerable to stored XSS resulting in attacker being able to execute JavaScript on the affected site","date":"2017-07-13"},{"id":"8e2b03c75a8a45c9e6799c08fd86769a9964d212","name":"Relevanssi \u2013 A Better Search <= 3.5.7.1 - Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/relevanssi\/relevanssi-a-better-search-3571-stored-cross-site-scripting","description":"WordPress plugin Relevanssi version 3.5.7.1 is vulnerable to stored XSS resulting in attacker being able to execute JavaScript on the affected site","date":"2017-02-28"},{"id":"b0417a54-084f-403d-baf1-8a27d7d49eb3","name":"Relevanssi &lt;= 3.5.7 - Stored Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/b0417a54-084f-403d-baf1-8a27d7d49eb3","description":"The Relevanssi &ndash; A Better Search WordPress plugin was affected by a Stored Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"4687cb5467f5f80e43c8c4227ed9d62b298d07e82b8aec7b3da122915d99b115","name":"Relevanssi &#8211; A Better Search [relevanssi] < 3.3.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2014-9443","name":"CVE-2014-9443","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2014-9443","description":"[en] Cross-site scripting (XSS) vulnerability in the Relevanssi plugin before 3.3.8 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.","date":"2015-01-02"},{"id":"bdea3b6b35e48dec6a17c92cf6d0d09203b3e8b4","name":"WordPress Relevanssi Plugin <= 3.3.7 - XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/relevanssi\/vulnerability\/wordpress-relevanssi-plugin-3-3-7-xss","description":"This vulnerability allows the attackers to inject arbitrary web script or HTML via unspecified vectors.\nUpdate the plugin.","date":"2015-01-02"},{"id":"cf35606a5dae00845f95c1bf847c09bbd66605bc","name":"Relevanssi \u2013 A Better Search < 3.3.8 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/relevanssi\/relevanssi-a-better-search-338-cross-site-scripting","description":"Cross-site scripting (XSS) vulnerability in the Relevanssi plugin before 3.3.8 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.","date":"2015-01-03"},{"id":"e471a980-cf06-42a1-b459-fcc3cc893ecc","name":"Relevanssi &lt;= 3.3.7.1 - Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/e471a980-cf06-42a1-b459-fcc3cc893ecc","description":"The Relevanssi &ndash; A Better Search WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"e7b7d9449a7b07ada727c20be883a722bfc60c6fd54b18ff8b4c09b834998b8e","name":"Relevanssi &#8211; A Better Search [relevanssi] < 2.7.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.7.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"df21da3493d505c0d60078b5df61ea0d06c877c0","name":"WordPress Relevanssi Plugin 2.7.2- Stored XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/relevanssi\/vulnerability\/wordpress-relevanssi-plugin-2-7-2-stored-xss","description":"Relevanssi plugin  is prone to a stored cross-site scripting vulnerability that exists because of \"search Query\" variable is displayed and logged unsanitized in the \"User Searches\" section in the admin Dashboard.  This vulnerability allows  an attacker to inject malicious HTML code.","date":"2011-02-24"}],"impact":[]},{"uuid":"be5435e9b9313b691604928d1187a637132a7f9bfdde2c3f04f9147ed1aaed42","name":"Relevanssi &#8211; A Better Search [relevanssi] < 4.14.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.14.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"a3cd21694e8358309f561ae40c7fe677b58a4501","name":"WordPress Relevanssi \u2013 A Better Search plugin <= 4.14.5 - Unauthorized AJAX Calls vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/relevanssi\/vulnerability\/wordpress-relevanssi-a-better-search-plugin-4-14-5-unauthorized-ajax-calls-vulnerability","description":"Unauthorized AJAX Calls vulnerability discovered by Jan w Oleju in WordPress Relevanssi \u2013 A Better Search plugin (versions <= 4.14.5).","date":"2022-02-15"}],"impact":[]},{"uuid":"a70c874b7c04ef2ef2d2c8ac9b4e55d7b8014b48938810ca59ed72a3a1525d1d","name":"Relevanssi &#8211; A Better Search [relevanssi] < 4.14.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.14.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"7bfa7991667663a75517e65650f2fcd4e823aaea","name":"WordPress Relevanssi plugin <= 4.14.2 - Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/relevanssi\/vulnerability\/wordpress-relevanssi-plugin-4-14-2-unauthenticated-stored-cross-site-scripting-xss-vulnerability","description":"Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress Relevanssi plugin (versions <= 4.14.2).","date":"2021-10-19"}],"impact":[]},{"uuid":"7ff97df359ff2b8bfecf18672bf87880ddad3a128d03008daac3342ba1c2290e","name":"Relevanssi &#8211; A Better Search [relevanssi] < 3.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"ecad5442ac171e61d727b8da522a107a38255289","name":"WordPress Relevanssi Plugin <= 3.2 - SQL Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/relevanssi\/vulnerability\/wordpress-relevanssi-plugin-3-2-sql-injection","description":"Because of this vulnerability, remote authenticated users can execute arbitrary SQL commands.\nUpdate the plugin.","date":"2015-05-15"}],"impact":[]},{"uuid":"33bead6344edfb1de6e4afd8051759b48f1ee7aa698ab00aa3086d9ba2a11bba","name":"Relevanssi &#8211; A Better Search [relevanssi] < 3.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"54bed89c3662291f27ed3be9c9ceaf08299ac168","name":"WordPress Relevanssi Plugin  - SQL Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/relevanssi\/vulnerability\/wordpress-relevanssi-plugin-sql-injection","description":"Relevanssi plugin is prone to an SQL injection. This vulnerability allows  an attacker to modify data, compromise the access and application or exploit hidden vulnerabilities in the underlying database.\nUpdate the plugin.","date":"2014-03-04"}],"impact":[]},{"uuid":"8af028629e53c18445ef4a011d3e3bb98308c554beca97c130332bc858e51209","name":"Relevanssi &#8211; A Better Search [relevanssi] < 4.14.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.14.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"c9f5e1b2369a93bc990d545aff97629a10b54712","name":"Relevanssi \u2013 A Better Search < 4.14.6 & Relevanssi \u2013 A Better Search Pro < 2.16.5 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/relevanssi-a-better-search-4146-relevanssi-a-better-search-pro-2165-missing-authorization","description":"The Relevanssi \u2013 A Better Search plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on several functions in versions before 4.14.6 in the free version and 2.16.5 in the PRO version. This makes it possible for authenticated attackers with Subscriber-level roles and above to perform unauthorized AJAX actions.","date":"2022-02-15"}],"impact":[]},{"uuid":"1c667bb9d9df2e94c615f298b4d5298042c8d4036880ec66d95d58612b953bfa","name":"Relevanssi &#8211; A Better Search [relevanssi] < 4.14.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.14.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"7cc11925a2930251c4369580d9374702abc4b8e9","name":"Relevanssi - A Better Search Free & Premium <= 2.16.3 & 4.14.3 - Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/relevanssi-a-better-search-free-premium-2163-4143-stored-cross-site-scripting","description":"The Relevanssi - A Better Search Free & Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018$query_link \u2019 parameter in versions up to, and including, 2.16.3 & 4.14.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2021-10-19"}],"impact":[]},{"uuid":"48763949b27dd0a7b143fa14ec121369f1f6cee35fd7374728a602f346ec4efa","name":"Relevanssi &#8211; A Better Search [relevanssi] < 3.6.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"8829d03c0347f2b086f6a549f57d6637abb356d7","name":"Relevanssi <= 3.6.0 - Authenticated (Admin+) SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/relevanssi\/relevanssi-360-authenticated-admin-sql-injection","description":"The Relevanssi plugin for WordPress is vulnerable to generic SQL Injection via the \u2018relevanssi_weight_\u2019 parameter in versions up to, and including, 3.6.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers with administrative privileges to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2018-04-10"}],"impact":[]},{"uuid":"8796237807fadfad34cad8210bf2ed117adf63a67cd0b8b863f40a92c3622f82","name":"Relevanssi &#8211; A Better Search [relevanssi] < 3.3.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"9ca33785bb0628030ed75b2ba3f6308cb414be9d","name":"Relevanssi <= 3.3 - SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/relevanssi\/relevanssi-33-sql-injection","description":"The Relevanssi plugin for WordPress is vulnerable to SQL Injection via the \u2018category_name\u2019 parameter in versions up to, and including, 3.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2014-02-25"}],"impact":[]},{"uuid":"877ea074e2de53e95881b2d520ea89584c0684d84148775b85ccad56db9334eb","name":"Relevanssi &#8211; A Better Search [relevanssi] < 4.14.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.14.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"c0c27674-715e-464d-ab38-0774128e6741","name":"Relevanssi - Subscriber+ Unauthorised AJAX Calls","link":"https:\/\/wpscan.com\/vulnerability\/c0c27674-715e-464d-ab38-0774128e6741","description":"The plugins do not have authorisation and CSRF checks in some of their AJAX actions, allowing any authenticated users, such as subscriber, to call them. This could disclose information to subscribers, as well as allow them to truncate the index, which will disable the search","date":null}],"impact":[]},{"uuid":"02f2e2d8ba8822221d0a17abeab89de3ffad654c892462b942a2b412cb14e048","name":"Relevanssi &#8211; A Better Search [relevanssi] < 4.14.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.14.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"ad08bd11-e4b0-4bb1-9481-3c9651f50466","name":"Relevanssi - A Better Search &lt; 4.14.3 - Unauthenticated Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/ad08bd11-e4b0-4bb1-9481-3c9651f50466","description":"The plugin does not sanitise and escape user searches before outputting them in the related admin dashboard when the feature is enabled","date":null}],"impact":[]},{"uuid":"9651cf8d2fed2c916fe2145278c96f09165dcee5cc9130e9d39fdb143a8453bb","name":"Relevanssi &#8211; A Better Search [relevanssi] < 3.6.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"04c725bb-7972-479f-88da-44b2d91f6698","name":"Relevanssi &lt;= 3.6.0 - Authenticated Admin SQL Injection","link":"https:\/\/wpscan.com\/vulnerability\/04c725bb-7972-479f-88da-44b2d91f6698","description":"The Relevanssi &ndash; A Better Search WordPress plugin was affected by an Authenticated Admin SQL Injection security vulnerability.","date":null}],"impact":[]},{"uuid":"b5d59752829167ddd876b570d5e2c44a1f420ad28c150ee82666cf3796ec8500","name":"Relevanssi &#8211; A Better Search [relevanssi] < 2.7.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.7.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"b072ba14-b3d8-45c9-9375-1e66066ed398","name":"Relevanssi 2.7.2 - Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/b072ba14-b3d8-45c9-9375-1e66066ed398","description":"The Relevanssi &ndash; A Better Search WordPress plugin was affected by a Stored XSS  security vulnerability.","date":null}],"impact":[]},{"uuid":"89e44de69204ce940b45f3311ef83100d8c47e060c7dffa9e37e2a6915c7a59d","name":"Relevanssi &#8211; A Better Search [relevanssi] < 3.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"a80953be-7032-412e-ba8c-33c04e16ba34","name":"Relevanssi 3.2 - Unspecified SQL Injection","link":"https:\/\/wpscan.com\/vulnerability\/a80953be-7032-412e-ba8c-33c04e16ba34","description":"The Relevanssi &ndash; A Better Search WordPress plugin was affected by an Unspecified SQL Injection security vulnerability.","date":null}],"impact":[]},{"uuid":"88262885a21a2b75ce44ed980024486faf6e10ea6bb2505fb3d71b42547f089f","name":"Relevanssi &#8211; A Better Search [relevanssi] < 4.22.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.22.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-7199","name":"CVE-2023-7199","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-7199","description":"[en] The Relevanssi WordPress plugin before 4.22.0, Relevanssi Premium WordPress plugin before 2.25.0 allows any unauthenticated user to read draft and private posts via a crafted request","date":"2024-01-29"},{"id":"8cd51efd1ba1c42a3c6b96e7c8a22b9be30409cf","name":"Relevanssi <= 4.21.2 (Free) and < 2.25.0 (Premium) - Missing Authorization to Unauthorized Post Access","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/relevanssi-4212-free-and-2250-premium-missing-authorization-to-unauthorized-post-access","description":"The Relevanssi \u2013 A Better Search plugin for WordPress is vulnerable to unauthorized access of data due to insufficient limitation of a user controlled key in all versions up to, and including, 4.21.2 (Free) and < 2.25.0 (Premium). This makes it possible for unauthenticated attackers to view private and draft posts that may contain sensitive information.","date":"2024-01-04"},{"id":"0c96a128-4473-41f5-82ce-94bba33ca4a3","name":"Relevanssi (Free &lt; 4.22.0, Premium &lt; 2.25.0) - Unauthenticated Private\/Draft Post Disclosure","link":"https:\/\/wpscan.com\/vulnerability\/0c96a128-4473-41f5-82ce-94bba33ca4a3","description":"The plugin allows any unauthenticated user to read draft and private posts via a crafted request","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-639","name":"Authorization Bypass Through User-Controlled Key","description":"The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data."}],"ssvc":{"exploitation":"poc","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"f462997e02a1a8c10e32f4b5f680890a0d399efeb876a5da6b25713e80d1b04a","name":"Relevanssi &#8211; A Better Search [relevanssi] < 4.22","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.22","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"50480344516a6faeef3c18ba92facd77a54898f1","name":"WordPress  Relevanssi  Plugin  < 4.22 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/relevanssi\/vulnerability\/wordpress-relevanssi-plugin-4-22-sensitive-data-exposure-vulnerability","description":"Update the WordPress Relevanssi plugin to the latest available version (at least 4.22).\nAn unknown person discovered and reported this Sensitive Data Exposure vulnerability in WordPress Relevanssi  Plugin.  This vulnerability has been fixed in version 4.22.\nHave additional information or questions about this entry? Get in touch.","date":null}],"impact":[]},{"uuid":"0b1fd80c47a4f0826a8526820277a380697f35ce7a3c3e44c1bd7261543c1fdd","name":"Relevanssi &#8211; A Better Search [relevanssi] < 4.22.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.22.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-1380","name":"CVE-2024-1380","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-1380","description":"[en] The Relevanssi \u2013 A Better Search plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relevanssi_export_log_check() function in all versions up to, and including, 4.22.0. This makes it possible for unauthenticated attackers to export the query log data. The vendor has indicated that they may look into adding a capability check for proper authorization control, however, this vulnerability is theoretically patched as is.","date":"2024-03-13"},{"id":"17caed94f283b5ef6cc73ed1edee49eb46bbfe2e","name":"Relevanssi \u2013 A Better Search <= 4.22.0 (Free) and <= 2.25.0 (Premium) - Missing Authorization to Unauthenticated Query Log Export","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/relevanssi\/relevanssi-a-better-search-4220-missing-authorization-to-unauthenticated-query-log-export","description":"The Relevanssi \u2013 A Better Search plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relevanssi_export_log_check() function in all versions up to, and including, 4.22.0 (Free) and 2.25.0 (Premium). This makes it possible for unauthenticated attackers to export the query log data. The vendor has indicated that they may look into adding a capability check for proper authorization control, however, this vulnerability is theoretically patched as is.","date":"2024-02-22"},{"id":"79c73a0a-087f-4971-a95f-c21d1d4db26e","name":"Relevanssi &lt; 4.22.1 - Unauthenticated Query Log Export","link":"https:\/\/wpscan.com\/vulnerability\/79c73a0a-087f-4971-a95f-c21d1d4db26e","description":"The plugin is vulnerable to unauthorized access of data due to a missing capability check on the relevanssi_export_log_check() function, allowing unauthenticated attackers to export the query log data. The vendor has indicated that they may look into adding a capability check for proper authorization control, however, this vulnerability is theoretically patched as is.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"ac4c5f3670fe4a639b8dcba18caafb4d7cb3e4edaaa9d8cfdb1a6d454f592aba","name":"Relevanssi &#8211; A Better Search [relevanssi] < 4.22.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.22.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-3214","name":"CVE-2024-3214","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-3214","description":"[en] The Relevanssi \u2013 A Better Search plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 4.22.1. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.","date":"2024-04-09"},{"id":"1e3b86298bd9eac9e15a193b786c7fc78c430bdc","name":"Relevanssi \u2013 A Better Search <= 4.22.1 - Unauthenticated Second Order CSV Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/relevanssi-a-better-search-4221-unauthenticated-second-order-csv-injection","description":"The Relevanssi \u2013 A Better Search plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 4.22.1. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.","date":"2024-04-04"},{"id":"9d49869b471049f415224527a801e5223f940fdb","name":"WordPress  Relevanssi  Plugin    <= 4.22.1 is vulnerable to CSV Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/relevanssi\/vulnerability\/wordpress-relevanssi-plugin-4-22-1-unauthenticated-second-order-csv-injection-vulnerability","description":"Update the WordPress Relevanssi plugin to the latest available version (at least 4.22.2).\nThura Moe Myint (mgthuramoemyint) discovered and reported this CSV Injection vulnerability in WordPress Relevanssi  Plugin. This could allow a malicious actor to craft malicious formulas to then exploit vulnerabilities in the spreadsheet software or to execute commands to gain access to the victim';s PC. This vulnerability has been fixed in version 4.22.2.\nHave additional information or questions about this entry? Get in touch.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-1236","name":"Improper Neutralization of Formula Elements in a CSV File","description":"The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"956c03fd0a699d87067ddb3d69bc89b6b48d2c8fa9267368b0d77148cb973b66","name":"Relevanssi &#8211; A Better Search [relevanssi] < 4.22.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.22.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-3213","name":"CVE-2024-3213","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-3213","description":"[en] The Relevanssi \u2013 A Better Search plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the relevanssi_update_counts() function in all versions up to, and including, 4.22.1. This makes it possible for unauthenticated attackers to execute expensive queries on the application that could lead into DOS.","date":"2024-04-09"},{"id":"22a25f68987819c5e0d2e822b9dfd1882e6cafd7","name":"Relevanssi \u2013 A Better Search <= 4.22.1 - Missing Authorization to Unauthenticated Count Option Update","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/relevanssi-a-better-search-4221-missing-authorization-to-unauthenticated-count-option-update","description":"The Relevanssi \u2013 A Better Search plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the relevanssi_update_counts() function in all versions up to, and including, 4.22.1. This makes it possible for unauthenticated attackers to execute expensive queries on the application that could lead into DOS.","date":"2024-04-04"},{"id":"0c4b03cd0775f3bb35e5d8bc3fc748127bfcc748","name":"WordPress  Relevanssi Premium Plugin    <= 2.25.1 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/relevanssi-premium\/vulnerability\/wordpress-relevanssi-premium-plugin-2-25-1-missing-authorization-to-unauthenticated-count-option-update-vulnerability","description":"Update the WordPress Relevanssi Premium plugin to the latest available version (at least 2.25.2).\nThura Moe Myint (mgthuramoemyint) discovered and reported this Broken Access Control vulnerability in WordPress Relevanssi Premium Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 2.25.2.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"74431c89763ddd230ad8f3fb54de0da304799410","name":"WordPress  Relevanssi  Plugin    <= 4.22.1 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/relevanssi\/vulnerability\/wordpress-relevanssi-plugin-4-22-1-missing-authorization-to-unauthenticated-count-option-update-vulnerability","description":"Update the WordPress Relevanssi plugin to the latest available version (at least 4.22.2).\nThura Moe Myint (mgthuramoemyint) discovered and reported this Broken Access Control vulnerability in WordPress Relevanssi  Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 4.22.2.\nHave additional information or questions about this entry? Get in touch.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"h","score":"8.2","severity":"h","exploitable":"3.9","impact":"4.2"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:H","score":"8.2","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"high","exploitable":"3.9","impact":"4.2"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"1d45d16fda64da71a8f2845662784ea02d6ee582fb22e9dfbb4a965b86430a12","name":"Relevanssi &#8211; A Better Search [relevanssi] < 4.23.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.23.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-7630","name":"CVE-2024-7630","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-7630","description":"[en] The Relevanssi \u2013 A Better Search plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.22.2 via the relevanssi_do_query() due to insufficient limitations on the posts that are returned when searching. This makes it possible for unauthenticated attackers to extract potentially sensitive information from password protected posts.","date":"2024-08-16"},{"id":"d78153faae87c8caccbf9a47ef6731e11e3e0712","name":"Relevanssi <= 4.22.2 (Free) and <= 2.25.1 (Premium) - Unauthenticated Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/relevanssi\/relevanssi-4222-unauthenticated-information-exposure","description":"The Relevanssi \u2013 A Better Search plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.22.2 (Free) and 2.25.1 (Premium) via the relevanssi_do_query() due to insufficient limitations on the posts that are returned when searching. This makes it possible for unauthenticated attackers to extract potentially sensitive information from password protected posts.","date":"2024-08-15"},{"id":"39f745d5f86d7e0a81472b999375c5a0ac39eca2","name":"WordPress Relevanssi Plugin <= 4.22.2 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/relevanssi\/vulnerability\/wordpress-relevanssi-plugin-4-22-2-unauthenticated-information-exposure-vulnerability","description":"<p>WordPress Relevanssi Plugin <= 4.22.2 is vulnerable to Sensitive Data Exposure<\/p><p>Software: Relevanssi<\/p><p>Link: https:\/\/wordpress.org\/plugins\/relevanssi\/#developers<\/p><p>Affected Version <= 4.22.2<\/p><p>Fixed in version 4.23.0 <\/p>","date":"2024-08-16"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"bc74e5c30b9ca4baf70ad6689a3c634e6ef0800575479bdc3fd5f03129dce70f","name":"Relevanssi &#8211; A Better Search [relevanssi] < 4.23.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.23.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-9021","name":"CVE-2024-9021","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-9021","description":"[en] In the process of testing the Relevanssi  WordPress plugin before 4.23.1, a vulnerability was found that allows you to implement Stored XSS on behalf of the Contributor+ by embedding malicious script, which entails account takeover backdoor","date":"2024-10-08"},{"id":"da6dffc90573eb1b031f3b1039cea2fd648a451e","name":"WordPress Relevanssi Plugin < 4.23.1 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/relevanssi\/vulnerability\/wordpress-relevanssi-plugin-4-23-1-contributor-stored-xss-vulnerability","description":"<p>WordPress Relevanssi Plugin < 4.23.1 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Relevanssi<\/p><p>Link: https:\/\/wordpress.org\/plugins\/relevanssi\/#developers<\/p><p>Affected Version < 4.23.1<\/p><p>Fixed in version 4.23.1 <\/p>","date":"2024-10-08"},{"id":"04c2d5d44a5ff897cca0abde29e658a2444fb61c","name":"Relevanssi \u2013 A Better Search <= 4.23.0 (Free) and <= 2.26.0 (Premium) - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/relevanssi\/relevanssi-a-better-search-4230-authenticated-contributor-stored-cross-site-scripting","description":"The Relevanssi \u2013 A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom name field in all versions up to, and including, 4.23.0 (Free) and 2.26.0 (Premium), due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-09-17"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"41bbe9d5483b4ff829b7b02e22cdb9185d207c1b3b347d5d995ffe2f8ae35ac9","name":"Relevanssi &#8211; A Better Search [relevanssi] < 4.24.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.24.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-4054","name":"Relevanssi <= 4.24.3 (Free) and <= 2.27.4 (Premium) - Unauthenticated Stored Cross-Site Scripting via Search Highlights","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-4054","description":"The Relevanssi \u2013 A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the highlights functionality in all versions up to, and including, 4.24.3 (Free) and <= 2.27.4 (Premium), due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page via the search results.","date":"0000-00-00"},{"id":"1efc09db431fa03cda1fe6f1b1a7a2d01b02ded0","name":"Relevanssi <= 4.24.3 (Free) and <= 2.27.4 (Premium) - Unauthenticated Stored Cross-Site Scripting via Search Highlights","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/relevanssi\/relevanssi-4243-unauthenticated-stored-cross-site-scripting-via-search-highlights","description":"The Relevanssi \u2013 A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the highlights functionality in all versions up to, and including, 4.24.3 (Free) and <= 2.27.4 (Premium), due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page via the search results.","date":"2025-05-06"},{"id":"EUVD-2025-13660","name":"EUVD-2025-13660","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-13660","description":"The Relevanssi \u2013 A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the highlights functionality in all versions up to, and including, 4.24.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page via the search results.","date":"2025-05-07"},{"id":"9f4ffa7917205c3089eab839f33dbd18ef097300","name":"WordPress Relevanssi Plugin <= 4.24.3 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/relevanssi\/vulnerability\/wordpress-relevanssi-plugin-4-24-3-unauthenticated-stored-cross-site-scripting-via-search-highlights-vulnerability","description":"<p>WordPress Relevanssi Plugin <= 4.24.3 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Relevanssi<\/p><p>Fixed in version 4.24.4 <\/p><p>Affected Version <= 4.24.3<\/p><p>CVE: CVE-2025-4054<\/p>","date":"2025-05-06"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.003"}},{"uuid":"a37db6a504043a28e7745d3ecbbb1483ec5a6de637d09faafdb32382f032f63a","name":"Relevanssi &#8211; A Better Search [relevanssi] < 4.24.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.24.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-4396","name":"Relevanssi <= 4.24.4 (Free) and <= 2.27.5 (Premium) - Unauthenticated SQL Injection","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-4396","description":"The Relevanssi \u2013 A Better Search plugin for WordPress is vulnerable to time-based SQL Injection via the cats and tags query parameters in all versions up to, and including, 4.24.4 (Free) and <= 2.27.5 (Premium) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries to already existing queries that can be used to extract sensitive information from the database.","date":"0000-00-00"},{"id":"ab0415734dd586d58420364c6dabccbe8310ad63","name":"Relevanssi <= 4.24.4 (Free) and <= 2.27.5 (Premium) - Unauthenticated SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/relevanssi-4244-free-and-2274-premium-unauthenticated-sql-injection","description":"The Relevanssi \u2013 A Better Search plugin for WordPress is vulnerable to time-based SQL Injection via the cats and tags query parameters in all versions up to, and including, 4.24.4 (Free) and <= 2.27.5 (Premium) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries to already existing queries that can be used to extract sensitive information from the database.","date":"2025-05-12"},{"id":"EUVD-2025-14360","name":"EUVD-2025-14360","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-14360","description":"The Relevanssi \u2013 A Better Search plugin for WordPress is vulnerable to time-based SQL Injection via the cats and tags query parameters in all versions up to, and including, 4.24.4 (Free) and <= 2.27.4 (Premium) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries to already existing queries that can be used to extract sensitive information from the database.","date":"2025-05-13"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"98df52b14d697e9b82ed9c8c0c283ae410d13dfbfc412f10940b9a93e836f869","name":"Relevanssi &#8211; A Better Search [relevanssi] < 4.24.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.24.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-5016","name":"Relevanssi <= 4.24.5 (Free) and <= 2.27.6 (Premium) - Unauthenticated Stored Cross-Site Scripting via Excerpt Highlights","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-5016","description":"The Relevanssi \u2013 A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Excerpt Highlights in all versions up to, and including, 4.24.5 (Free) and 2.27.6 (Premium) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"0000-00-00"},{"id":"3e4f966663aad6bf89d3fd7a803df9e0dc01cd0d","name":"Relevanssi <= 4.24.5 (Free) and <= 2.27.6 (Premium) - Unauthenticated Stored Cross-Site Scripting via Excerpt Highlights","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/relevanssi-4245-free-and-2276-premium-unauthenticated-stored-cross-site-scripting-via-excerpt-highlights","description":"The Relevanssi \u2013 A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Excerpt Highlights in all versions up to, and including, 4.24.5 (Free) and 2.27.6 (Premium) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-05-30"},{"id":"EUVD-2025-16540","name":"EUVD-2025-16540","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-16540","description":"The Relevanssi \u2013 A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Excerpt Highlights in all versions up to, and including, 4.24.5 (Free) and 2.27.6 (Premium) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-05-31"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"h","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.7","severity":"m","exploitable":"1.6","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.7","severity":"medium","av":"network","ac":"high","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.6","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.002"}},{"uuid":"ac149491c6fcccc134ac69e29ea4075435a8b3cd68c6b97e8e3feb183e8d751f","name":"Relevanssi &#8211; A Better Search [relevanssi] < 4.26.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.26.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-14719","name":"CVE-2025-14719","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-14719","description":"[en] The Relevanssi  WordPress plugin before 4.26.0, Relevanssi Premium WordPress plugin before 2.29.0 do not sanitize and escape a parameter before using it in a SQL statement, allowing contributor and above roles to perform SQL injection attacks","date":"2026-01-07"},{"id":"71b354e394438787f0a8b4f3b022a5d1e5434477","name":"Relevanssi < 4.26.0 (Free) < 2.29.0 (Premium) - Authenticated (Contributor+) SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/relevanssi-4260-free-2290-premium-authenticated-contributor-sql-injection","description":"The Relevanssi Premium plugin for WordPress is vulnerable to SQL Injection in all versions up to 4.26.0 (Free) & 2.29.0 (Premium) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2025-12-17"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"4.9","severity":"m","exploitable":"1.2","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"4.9","severity":"medium","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"1.2","impact":"3.6"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"8b268a561f889d514a1cf73954d1d7a5a8c5e3d98ee176e7fbd72f17a5200016","name":"Relevanssi &#8211; A Better Search [relevanssi] < 4.27.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.27.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-15941","name":"CVE-2026-15941","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-15941","description":"[en] The plugin provides an Admin Search page that allows users with the `edit_posts` capability to run Relevanssi searches from the WordPress dashboard. The AJAX handler accepts a URL-encoded `args` parameter, parses it into a `WP_Query`, and then passes user-controlled taxonomy query data into Relevanssi's taxonomy restriction builder. The taxonomy value is sanitized as text but is not parameterized for SQL before being interpolated into a term taxonomy lookup query. This allows an authenticated contributor-level attacker to inject SQL through the Admin Search AJAX request and execute time-based blind SQL injection against the WordPress database.","date":"2026-08-05"},{"id":"7c211320a1a47af65e1c5b88abff349e9d9cc502","name":"Relevanssi <= 4.27.1 and Relevanssi Premium <= 2.30.2 - Authenticated (Contributor+) SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/id\/4f96b87a-1405-4cf6-b903-ad0c7c8e2826","description":"The plugin provides an Admin Search page that allows users with the `edit_posts` capability to run Relevanssi searches from the WordPress dashboard. The AJAX handler accepts a URL-encoded `args` parameter, parses it into a `WP_Query`, and then passes user-controlled taxonomy query data into Relevanssi's taxonomy restriction builder. The taxonomy value is sanitized as text but is not parameterized for SQL before being interpolated into a term taxonomy lookup query. This allows an authenticated contributor-level attacker to inject SQL through the Admin Search AJAX request and execute time-based blind SQL injection against the WordPress database.","date":"2026-08-04"},{"id":"83e4e34f1f2d832b6aabdb65d2696611ab9b27c5","name":"Relevanssi <= 4.27.1 and Relevanssi Premium <= 2.30.2 - Authenticated (Contributor+) SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/relevanssi-4271-and-relevanssi-premium-2302-authenticated-contributor-sql-injection","description":"","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"6.5","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"33ce0621e5b9ab163420df674cfeda83c9e380b9a6494a555818493024e3a86a","name":"Relevanssi &#8211; A Better Search [relevanssi] < 4.28.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.28.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-19985","name":"CVE-2026-19985","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-19985","description":"[en] The Relevanssi \u2013 A Better Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.28.1 via the 's', 'post_types', and 'orderby' request parameters. This is due to insufficient input sanitization and output escaping in the relevanssi_debug_array() function in lib\/debug.php, which dumps user-supplied query variables through print_r() inside a <pre> block without HTML escaping. The debug path is enabled by supplying the relevanssi_debug=on request parameter when the administrator has previously enabled the 'Debugging mode' setting; the gate itself is a configuration check with no capability, nonce, or logged-in check (the vendor explicitly suppresses nonce verification on that line). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link.","date":"2026-09-11"},{"id":"926ee514f4415447896ef23702ecd56ee8e83719","name":"Relevanssi <= 4.28.1 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/relevanssi\/relevanssi-4281-reflected-cross-site-scripting","description":"The Relevanssi \u2013 A Better Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.28.1 via the 's', 'post_types', and 'orderby' request parameters. This is due to insufficient input sanitization and output escaping in the relevanssi_debug_array() function in lib\/debug.php, which dumps user-supplied query variables through print_r() inside a <pre> block without HTML escaping. The debug path is enabled by supplying the relevanssi_debug=on request parameter when the administrator has previously enabled the 'Debugging mode' setting; the gate itself is a configuration check with no capability, nonce, or logged-in check (the vendor explicitly suppresses nonce verification on that line). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link.","date":"2026-08-04"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1789100971"}