Input validation vulnerability in Relevanssi – A Better Search (Pro) 2.27.4

A popular plugin for WordPress, called Relevanssi, has a security vulnerability that allows attackers to access sensitive information from the website’s database. This is done by adding additional queries to the existing ones through the “cats” and “tags” parameters. The vulnerable versions are up to 4.24.4 for the free version and 2.27.5 for the premium version. This means that even unauthenticated users can exploit this vulnerability.

Detected in:

Relevanssi – A Better Search fixed vulnerable versions: >= * <= 4.24.4
Relevanssi – A Better Search (Pro) fixed vulnerable versions: >= * <= 2.27.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.