CVE-2024-1380

MEDIUM NUCLEI

Relevanssi < 4.22.1 and Relevanssi Premium < 2.25.0 - Unauthenticated Query Log Data Export

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-1380. PoCs published by RandomRobbieBF. A Nuclei detection template is also available.

AI-analyzed exploit summary This repository contains a functional proof-of-concept for CVE-2024-1380, demonstrating an unauthorized data access vulnerability in the Relevanssi WordPress plugin. The PoC includes a crafted HTTP request that exploits a missing capability check to export query log data without authentication.

Description

The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relevanssi_export_log_check() function in all versions up to, and including, 4.22.0 (Free) and 2.25.0 (Premium). This makes it possible for unauthenticated attackers to export the query log data. The vendor has indicated that they may look into adding a capability check for proper authorization control, however, this vulnerability is theoretically patched as is.

Exploits (1)

nomisec WORKING POC 1 stars
by RandomRobbieBF · poc
https://github.com/RandomRobbieBF/CVE-2024-1380

This repository contains a functional proof-of-concept for CVE-2024-1380, demonstrating an unauthorized data access vulnerability in the Relevanssi WordPress plugin. The PoC includes a crafted HTTP request that exploits a missing capability check to export query log data without authentication.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Relevanssi – A Better Search <= 4.22.0
No auth needed
Prerequisites: WordPress site with Relevanssi plugin installed and logging enabled
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Nuclei Templates (1)

Relevanssi (A Better Search) <= 4.22.0 - Query Log Export
MEDIUMVERIFIEDby FLX
FOFA: /wp-content/plugins/relevanssi/

Scores

CVSS v3 5.3
EPSS 0.5019
EPSS Percentile 98.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (3)
comesio/Relevanssi – A Better Search < 4.22.0
relevanssi/relevanssi < 4.22.1
Relevanssi/Relevanssi Premium < 2.25.0
Published Mar 13, 2024
Tracked Since Feb 18, 2026