Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 05 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 05 Aug 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Comesio
Comesio relevanssi – A Better Search Relevanssi Relevanssi relevanssi Premium – A Better Search Wordpress Wordpress wordpress |
|
| Vendors & Products |
Comesio
Comesio relevanssi – A Better Search Relevanssi Relevanssi relevanssi Premium – A Better Search Wordpress Wordpress wordpress |
Wed, 05 Aug 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The plugin provides an Admin Search page that allows users with the `edit_posts` capability to run Relevanssi searches from the WordPress dashboard. The AJAX handler accepts a URL-encoded `args` parameter, parses it into a `WP_Query`, and then passes user-controlled taxonomy query data into Relevanssi's taxonomy restriction builder. The taxonomy value is sanitized as text but is not parameterized for SQL before being interpolated into a term taxonomy lookup query. This allows an authenticated contributor-level attacker to inject SQL through the Admin Search AJAX request and execute time-based blind SQL injection against the WordPress database. | |
| Title | Relevanssi <= 4.27.1 and Relevanssi Premium <= 2.30.2 - Authenticated (Contributor+) SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-08-05T15:52:33.819Z
Reserved: 2026-07-16T08:59:41.548Z
Link: CVE-2026-15941
Updated: 2026-08-05T15:52:29.194Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-05T10:18:31Z