CVE-2024-7630

MEDIUM

Relevanssi < 4.23.0 and Premium < 2.25.1 - Unauthenticated Sensitive Information Exposure via Search Query

Title source: llm
STIX 2.1

Description

The Relevanssi – A Better Search plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.22.2 (Free) and 2.25.1 (Premium) via the relevanssi_do_query() due to insufficient limitations on the posts that are returned when searching. This makes it possible for unauthenticated attackers to extract potentially sensitive information from password protected posts.

Scores

CVSS v3 5.3
EPSS 0.0048
EPSS Percentile 37.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (3)
comesio/Relevanssi – A Better Search < 4.22.2
relevanssi/relevanssi < 4.23.0
Relevanssi/Relevanssi Premium < 2.25.1
Published Aug 16, 2024
Tracked Since Feb 18, 2026