Relevanssi WordPress Plugin Time-Based SQL Injection Vulnerability

Vulnerability

A time-based SQL injection vulnerability has been identified in the Relevanssi – A Better Search plugin for WordPress. This issue affects all versions prior to and including 4.24.4 (Free) and 2.27.4 (Premium). The vulnerability arises from inadequate escaping of user-supplied parameters in the cats and tags query parameters, coupled with a lack of proper preparation in the existing SQL query. As a result, unauthenticated attackers can append additional SQL queries to existing ones, potentially leading to the extraction of sensitive information from the database.

Impact

Exploitation of this vulnerability allows for time-based SQL injection, where an attacker can manipulate SQL queries to extract sensitive information from the database.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
2.5
exploitability
9.0
remediation
0.0
relevance
0.0
threat
3.6
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.