Relevanssi
cpe:2.3:a:relevanssi:relevanssi:*:*:*:*:wordpress:*:*
- <= 4.24.4
- <= 2.27.4
A time-based SQL injection vulnerability has been identified in the Relevanssi – A Better Search plugin for WordPress. This issue affects all versions prior to and including 4.24.4 (Free) and 2.27.4 (Premium). The vulnerability arises from inadequate escaping of user-supplied parameters in the cats and tags query parameters, coupled with a lack of proper preparation in the existing SQL query. As a result, unauthenticated attackers can append additional SQL queries to existing ones, potentially leading to the extraction of sensitive information from the database.
Exploitation of this vulnerability allows for time-based SQL injection, where an attacker can manipulate SQL queries to extract sensitive information from the database.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.