cbcvebase.

Comesio Relevanssi A Better Search vulnerabilities

7 known vulnerabilities affecting comesio/relevanssi_a_better_search.

Total CVEs
7
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH3MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2025-4396P1HIGHCVSS 7.5ExploitedPoC≤ 4.24.42025-05-13
CVE-2025-4396 [HIGH] CWE-89 CVE-2025-4396: The Relevanssi – A Better Search plugin for WordPress is vulnerable to time-based SQL Injection via The Relevanssi – A Better Search plugin for WordPress is vulnerable to time-based SQL Injection via the cats and tags query parameters in all versions up to, and including, 4.24.4 (Free) and <= 2.27.5 (Premium) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible f
nvd
CVE-2024-1380P3MEDIUMCVSS 5.3PoC≤ 4.22.02024-03-13
CVE-2024-1380 [MEDIUM] CWE-862 CVE-2024-1380: The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized access of data d The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relevanssi_export_log_check() function in all versions up to, and including, 4.22.0 (Free) and 2.25.0 (Premium). This makes it possible for unauthenticated attackers to export the query log data. The vendor has in
nvd
CVE-2024-3214P3CRITICALCVSS 9.8≤ 4.22.12024-04-09
CVE-2024-3214 [CRITICAL] CWE-1236 CVE-2024-3214: The Relevanssi – A Better Search plugin for WordPress is vulnerable to CSV Injection in all versions The Relevanssi – A Better Search plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 4.22.1. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable co
nvd
CVE-2024-3213P3HIGHCVSS 8.2≤ 4.22.12024-04-09
CVE-2024-3213 [HIGH] CWE-862 CVE-2024-3213: The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized modification of The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the relevanssi_update_counts() function in all versions up to, and including, 4.22.1. This makes it possible for unauthenticated attackers to execute expensive queries on the application that could lead into DOS.
nvd
CVE-2024-7630P3HIGHCVSS 7.5≤ 4.22.22024-08-16
CVE-2024-7630 [HIGH] CWE-200 CVE-2024-7630: The Relevanssi – A Better Search plugin for WordPress is vulnerable to Information Exposure in all v The Relevanssi – A Better Search plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.22.2 (Free) and 2.25.1 (Premium) via the relevanssi_do_query() due to insufficient limitations on the posts that are returned when searching. This makes it possible for unauthenticated attackers to extract potentially sensi
nvd
CVE-2025-4054P4MEDIUMCVSS 6.1≤ 4.24.32025-05-07
CVE-2025-4054 [MEDIUM] CWE-79 CVE-2025-4054: The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting v The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the highlights functionality in all versions up to, and including, 4.24.3 (Free) and <= 2.27.4 (Premium), due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts
nvd
CVE-2025-5016P4MEDIUMCVSS 4.7≤ 4.24.52025-05-31
CVE-2025-5016 [MEDIUM] CWE-79 CVE-2025-5016: The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting v The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Excerpt Highlights in all versions up to, and including, 4.24.5 (Free) and 2.27.6 (Premium) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages t
nvd
Comesio Relevanssi A Better Search vulnerabilities | cvebase