PT-2025-20826 · WordPress · Relevanssi

Jack Taylor

·

Published

2025-05-13

·

Updated

2026-04-13

·

CVE-2025-4396

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Relevanssi – A Better Search plugin for WordPress versions 4.24.4 and earlier (Free) and versions 2.27.4 and earlier (Premium)
Description The Relevanssi – A Better Search plugin for WordPress is vulnerable to time-based SQL Injection via the cats and tags query parameters due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries to already existing queries that can be used to extract sensitive information from the database.
Recommendations For Relevanssi – A Better Search plugin for WordPress versions 4.24.4 and earlier (Free) and versions 2.27.4 and earlier (Premium), update to a version that fixes the SQL Injection issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-4396

Affected Products

Relevanssi