CVE-2024-7630
MEDIUMRelevanssi < 4.23.0 and Premium < 2.25.1 - Unauthenticated Sensitive Information Exposure via Search Query
Title source: llmDescription
The Relevanssi – A Better Search plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.22.2 (Free) and 2.25.1 (Premium) via the relevanssi_do_query() due to insufficient limitations on the posts that are returned when searching. This makes it possible for unauthenticated attackers to extract potentially sensitive information from password protected posts.
References (2)
Core 2
Scores
CVSS v3
5.3
EPSS
0.0048
EPSS Percentile
37.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-200
Status
published
Products (3)
comesio/Relevanssi – A Better Search
< 4.22.2
relevanssi/relevanssi
< 4.23.0
Relevanssi/Relevanssi Premium
< 2.25.1
Published
Aug 16, 2024
Tracked Since
Feb 18, 2026