CVE-2026-15941 PUBLISHED

Relevanssi <= 4.27.1 and Relevanssi Premium <= 2.30.2 - Authenticated (Contributor+) SQL Injection

Assigner: Wordfence
Reserved: 16.07.2026 Published: 05.08.2026 Updated: 05.08.2026

The plugin provides an Admin Search page that allows users with the edit_posts capability to run Relevanssi searches from the WordPress dashboard. The AJAX handler accepts a URL-encoded args parameter, parses it into a WP_Query, and then passes user-controlled taxonomy query data into Relevanssi's taxonomy restriction builder. The taxonomy value is sanitized as text but is not parameterized for SQL before being interpolated into a term taxonomy lookup query. This allows an authenticated contributor-level attacker to inject SQL through the Admin Search AJAX request and execute time-based blind SQL injection against the WordPress database.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 6.5

Product Status

Vendor Relevanssi
Product Relevanssi Premium – A Better Search
Versions Default: unaffected
  • affected from 0 to 2.30.2 (incl.)
Vendor comesio
Product Relevanssi – A Better Search
Versions Default: unaffected
  • affected from 0 to 4.27.1 (incl.)

Credits

  • daroo finder

References

Problem Types

  • CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CWE