Vulnerabilities > Relevanssi > Relevanssi > 2.8.1

DATE CVE VULNERABILITY TITLE RISK
2024-08-16 CVE-2024-7630 Unspecified vulnerability in Relevanssi
The Relevanssi – A Better Search plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.22.2 via the relevanssi_do_query() due to insufficient limitations on the posts that are returned when searching.
network
low complexity
relevanssi
7.5
2024-04-09 CVE-2024-3213 Missing Authorization vulnerability in Relevanssi
The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the relevanssi_update_counts() function in all versions up to, and including, 4.22.1.
network
low complexity
relevanssi CWE-862
8.2
2024-04-09 CVE-2024-3214 Improper Neutralization of Formula Elements in a CSV File vulnerability in Relevanssi
The Relevanssi – A Better Search plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 4.22.1.
network
low complexity
relevanssi CWE-1236
critical
9.8
2024-01-29 CVE-2023-7199 Authorization Bypass Through User-Controlled Key vulnerability in Relevanssi
The Relevanssi WordPress plugin before 4.22.0, Relevanssi Premium WordPress plugin before 2.25.0 allows any unauthenticated user to read draft and private posts via a crafted request
network
low complexity
relevanssi CWE-639
5.3
2018-04-04 CVE-2018-9034 Cross-site Scripting vulnerability in Relevanssi
Cross-site scripting (XSS) vulnerability in lib/interface.php of the Relevanssi plugin 4.0.4 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the tab GET parameter.
network
low complexity
relevanssi CWE-79
5.4