Extension WordPress
Vulnérabilités Relevanssi – A Better Search
Cette page rassemble les failles publiées pour Relevanssi – A Better Search, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Relevanssi – A Better Search
17 fiches
Relevanssi < 4.26.0 (Free) < 2.29.0 (Premium) – Authenticated (Contributor+) SQL Injection
The Relevanssi Premium plugin for WordPress is vulnerable to SQL Injection in all versions up to 4.26.0 (Free) & 2.29.0 (Premium) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…
[*, 4.26.0)
4.26.0
17/12/2025
Relevanssi <= 4.24.5 (Free) and <= 2.27.6 (Premium) – Unauthenticated Stored Cross-Site Scripting via Excerpt Highlights
The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Excerpt Highlights in all versions up to, and including, 4.24.5 (Free) and 2.27.6 (Premium) due to insufficient input sanitization and output…
*-4.24.5
4.24.6
30/05/2025
Relevanssi <= 4.24.4 (Free) and <= 2.27.5 (Premium) – Unauthenticated SQL Injection
The Relevanssi – A Better Search plugin for WordPress is vulnerable to time-based SQL Injection via the cats and tags query parameters in all versions up to, and including, 4.24.4 (Free) and
*-4.24.4
4.24.5
12/05/2025
Relevanssi <= 4.24.3 (Free) and <= 2.27.4 (Premium) – Unauthenticated Stored Cross-Site Scripting via Search Highlights
The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the highlights functionality in all versions up to, and including, 4.24.3 (Free) and
*-4.24.3
4.24.4
06/05/2025
Relevanssi – A Better Search <= 4.23.0 (Free) and <= 2.26.0 (Premium) – Authenticated (Contributor+) Stored Cross-Site Scripting
The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom name field in all versions up to, and including, 4.23.0 (Free) and 2.26.0 (Premium), due to insufficient input sanitization and output…
*-4.23.0
4.23.1
17/09/2024
Relevanssi <= 4.22.2 (Free) and <= 2.25.1 (Premium) – Unauthenticated Information Exposure
The Relevanssi – A Better Search plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.22.2 (Free) and 2.25.1 (Premium) via the relevanssi_do_query() due to insufficient limitations on the posts that are…
*-4.22.2
4.23.0
15/08/2024
Relevanssi – A Better Search <= 4.22.1 – Missing Authorization to Unauthenticated Count Option Update
The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the relevanssi_update_counts() function in all versions up to, and including, 4.22.1. This makes it possible…
*-4.22.1
4.22.2
04/04/2024
Relevanssi – A Better Search <= 4.22.1 – Unauthenticated Second Order CSV Injection
The Relevanssi – A Better Search plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 4.22.1. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which…
*-4.22.1
4.22.2
04/04/2024
Relevanssi – A Better Search <= 4.22.0 (Free) and <= 2.25.0 (Premium) – Missing Authorization to Unauthenticated Query Log Export
The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relevanssi_export_log_check() function in all versions up to, and including, 4.22.0 (Free) and 2.25.0 (Premium).…
*-4.22.0
4.22.1
22/02/2024
Relevanssi <= 4.21.2 (Free) and < 2.25.0 (Premium) – Missing Authorization to Unauthorized Post Access
The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized access of data due to insufficient limitation of a user controlled key in all versions up to, and including, 4.21.2 (Free) and < 2.25.0 (Premium).…
*-4.21.2
4.22.0
04/01/2024
Relevanssi – A Better Search < 4.14.6 & Relevanssi – A Better Search Pro < 2.16.5 – Missing Authorization
The Relevanssi – A Better Search plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on several functions in versions before 4.14.6 in the free version and 2.16.5 in the PRO version. This makes…
[*, 4.14.6)
4.14.6
15/02/2022
Relevanssi – A Better Search Free & Premium <= 2.16.3 & 4.14.3 – Stored Cross-Site Scripting
The Relevanssi – A Better Search Free & Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘$query_link ’ parameter in versions up to, and including, 2.16.3 & 4.14.3 due to insufficient input sanitization and…
[*, 4.14.3)
4.14.4
19/10/2021
Relevanssi <= 3.6.0 – Authenticated (Admin+) SQL Injection
The Relevanssi plugin for WordPress is vulnerable to generic SQL Injection via the ‘relevanssi_weight_’ parameter in versions up to, and including, 3.6.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…
[*, 3.6.1)
3.6.1
10/04/2018
Relevanssi <= 4.0.4 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in lib/interface.php of the Relevanssi plugin 4.0.4 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the tab GET parameter.
*-4.0.4
4.0.5
30/03/2018
Relevanssi – A Better Search <= 3.5.7.1 – Stored Cross-Site Scripting
WordPress plugin Relevanssi version 3.5.7.1 is vulnerable to stored XSS resulting in attacker being able to execute JavaScript on the affected site
[*, 3.5.8)
3.5.8
28/02/2017
Relevanssi – A Better Search < 3.3.8 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Relevanssi plugin before 3.3.8 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
[*, 3.3.8)
3.3.8
03/01/2015
Relevanssi <= 3.3 – SQL Injection
The Relevanssi plugin for WordPress is vulnerable to SQL Injection via the ‘category_name’ parameter in versions up to, and including, 3.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…
*-3.3
3.3.1
25/02/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.