CVE-2024-3214

MEDIUM

Relevanssi - A Better Search <4.22.1 - Code Injection

Title source: llm
STIX 2.1

Description

The Relevanssi – A Better Search plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 4.22.1. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.

Scores

CVSS v3 5.8
EPSS 0.0239
EPSS Percentile 85.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-1236
Status published
Products (3)
comesio/Relevanssi – A Better Search < 4.22.1
relevanssi/relevanssi < 4.22.2
Relevanssi/Relevanssi Premium < 2.25.1
Published Apr 09, 2024
Tracked Since Feb 18, 2026