Access violation vulnerability in Relevanssi – A Better Search 4.22.0

The Relevanssi plugin for WordPress, which helps improve search results, has a security flaw that allows unauthorized access to data. This is because a function called relevanssi_export_log_check() does not have a check to ensure only authorized users can access it. This means that attackers who are not logged in can export the search query log data. The creators of the plugin have said they might add a check to prevent this, but for now, the vulnerability remains.

Detected in:

Relevanssi – A Better Search fixed vulnerable versions: >= * <= 4.22.0
Relevanssi – A Better Search (Pro) fixed vulnerable versions: >= * <= 2.25.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.