cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forrelevanssi relevanssi

Direction: ascending
Jun 07, 2024

Relevanssi – A Better Search # CVE-2014-9443

CVE, Research URL

CVE-2014-9443

Date
Jan 03, 2015
Research Description
Cross-site scripting (XSS) vulnerability in the Relevanssi plugin before 3.3.8 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected versions
Min -, max -.
Status
vulnerable

Relevanssi – A Better Search # CVE-2018-9034

CVE, Research URL

CVE-2018-9034

Date
Apr 05, 2018
Research Description
Cross-site scripting (XSS) vulnerability in lib/interface.php of the Relevanssi plugin 4.0.4 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the tab GET parameter.
Affected versions
Min -, max -.
Status
vulnerable

Relevanssi – A Better Search # CVE-2017-1000038

CVE, Research URL

CVE-2017-1000038

Date
Jul 17, 2017
Research Description
WordPress plugin Relevanssi version 3.5.7.1 is vulnerable to stored XSS resulting in attacker being able to execute JavaScript on the affected site
Affected versions
Min -, max -.
Status
vulnerable

Relevanssi – A Better Search # CVE-2023-7199

CVE, Research URL

CVE-2023-7199

Date
Jan 29, 2024
Research Description
The Relevanssi WordPress plugin before 4.22.0, Relevanssi Premium WordPress plugin before 2.25.0 allows any unauthenticated user to read draft and private posts via a crafted request
Affected versions
Min -, max -.
Status
vulnerable

Relevanssi – A Better Search # CVE-2024-3213

CVE, Research URL

CVE-2024-3213

Date
Apr 10, 2024
Research Description
The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the relevanssi_update_counts() function in all versions up to, and including, 4.22.1. This makes it possible for unauthenticated attackers to execute expensive queries on the application that could lead into DOS.
Affected versions
Min -, max -.
Status
vulnerable

Relevanssi – A Better Search # CVE-2024-1380

CVE, Research URL

CVE-2024-1380

Date
Mar 13, 2024
Research Description
The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relevanssi_export_log_check() function in all versions up to, and including, 4.22.0. This makes it possible for unauthenticated attackers to export the query log data. The vendor has indicated that they may look into adding a capability check for proper authorization control, however, this vulnerability is theoretically patched as is.
Affected versions
Min -, max -.
Status
vulnerable

Relevanssi – A Better Search # CVE-2024-3214

CVE, Research URL

CVE-2024-3214

Date
Apr 10, 2024
Research Description
The Relevanssi – A Better Search plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 4.22.1. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
Affected versions
Min -, max -.
Status
vulnerable
Aug 16, 2024

Relevanssi – A Better Search # CVE-2024-7630

CVE, Research URL

CVE-2024-7630

Date
Aug 16, 2024
Research Description
The Relevanssi – A Better Search plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.22.2 via the relevanssi_do_query() due to insufficient limitations on the posts that are returned when searching. This makes it possible for unauthenticated attackers to extract potentially sensitive information from password protected posts.
Affected versions
Min -, max -.
Status
vulnerable
Oct 10, 2024

Relevanssi – A Better Search # CVE-2024-9021

CVE, Research URL

CVE-2024-9021

Date
Oct 08, 2024
Research Description
In the process of testing the Relevanssi WordPress plugin before 4.23.1, a vulnerability was found that allows you to implement Stored XSS on behalf of the Contributor+ by embedding malicious script, which entails account takeover backdoor
Affected versions
Min -, max -.
Status
vulnerable
May 07, 2025

Relevanssi – A Better Search # CVE-2025-4054

CVE, Research URL

CVE-2025-4054

Date
May 07, 2025
Research Description
The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the highlights functionality in all versions up to, and including, 4.24.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page via the search results.
Affected versions
Min -, max -.
Status
vulnerable