Relevanssi · Relevanssi Premium · CVE-2017-1000225
**Name of the Vulnerable Software and Affected Versions**
Relevanssi Premium version 1.14.8
**Description**
The issue is related to a Reflected XSS in Relevanssi Premium. This could allow an unauthenticated attacker to perform actions similar to those of an admin when the `relevanssi didyoumean()` function is used.
**Recommendations**
For Relevanssi Premium version 1.14.8, consider disabling the `relevanssi didyoumean()` function until a patch is available to prevent potential exploitation.