CVE-2024-3214
MEDIUMRelevanssi - A Better Search <4.22.1 - Code Injection
Title source: llmDescription
The Relevanssi – A Better Search plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 4.22.1. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
Scores
CVSS v3
5.8
EPSS
0.0239
EPSS Percentile
85.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-1236
Status
published
Products (3)
comesio/Relevanssi – A Better Search
< 4.22.1
relevanssi/relevanssi
< 4.22.2
Relevanssi/Relevanssi Premium
< 2.25.1
Published
Apr 09, 2024
Tracked Since
Feb 18, 2026